hormuz-strait

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses curl to fetch data from https://hormuzstraitmonitor.com/api/dashboard. While this is central to its stated purpose, the domain is not in the trusted or well-known service categories.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from an external API, which could potentially contain malicious instructions intended to influence the agent's behavior.
  • Ingestion points: SKILL.md retrieves content from the external dashboard API via curl.
  • Boundary markers: Absent; the instructions do not provide specific delimiters or warnings to the agent to disregard potential instructions embedded in the API response.
  • Capability inventory: The skill is restricted to reading data and formatting it for the user; it does not possess file-writing or system-level command execution capabilities beyond the initial curl fetch.
  • Sanitization: Absent; there is no mention of filtering or validating the API content before the agent processes and presents it to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:06 AM