hormuz-strait
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
curlto fetch data fromhttps://hormuzstraitmonitor.com/api/dashboard. While this is central to its stated purpose, the domain is not in the trusted or well-known service categories. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from an external API, which could potentially contain malicious instructions intended to influence the agent's behavior.
- Ingestion points:
SKILL.mdretrieves content from the external dashboard API viacurl. - Boundary markers: Absent; the instructions do not provide specific delimiters or warnings to the agent to disregard potential instructions embedded in the API response.
- Capability inventory: The skill is restricted to reading data and formatting it for the user; it does not possess file-writing or system-level command execution capabilities beyond the initial
curlfetch. - Sanitization: Absent; there is no mention of filtering or validating the API content before the agent processes and presents it to the user.
Audit Metadata