hydro-plugin-services
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The documentation defines APIs that ingest untrusted external data and provide powerful capabilities for file manipulation and network interaction.
- Ingestion points: Data received via
OAuthProvider.callbackand file uploads throughStorageModel.put(SKILL.md). - Boundary markers: Not explicitly specified within the API documentation context.
- Capability inventory: File system access (
StorageModel), network requests (superagent), and task persistence (TaskModel,ScheduleModel) (SKILL.md). - Sanitization: Recommends using
Schemasteryfor input validation andTokenModelfor state verification. - [COMMAND_EXECUTION]: Describes programmatic access to the local filesystem and S3-compatible storage via the
StorageModelandLocalStorageServiceAPIs. - [CREDENTIALS_UNSAFE]: Contains detailed instructions on how to handle API keys and secrets securely, specifically demonstrating the use of
role('secret')in schemas and theFLAG_SECRETflag to ensure sensitive values are encrypted at rest and masked in management interfaces.
Audit Metadata