skills/iblai/api/iblai-api-catalog/Gen Agent Trust Hub

iblai-api-catalog

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Instructions include the use of /iblai-api-login to initialize session environment variables. This is a functional requirement for the vendor's authentication flow.- [DATA_EXPOSURE]: The skill communicates with api.iblai.app to retrieve and modify organizational and user data. These network operations are consistent with the skill's stated purpose as a catalog management tool.- [PROMPT_INJECTION]: The skill retrieves user-generated content, such as course reviews, from the API. While this creates a surface for indirect prompt injection, the risk is inherent to the use case and occurs within a trusted vendor context. Ingestion points: GET /api/catalog/reviews/course/ and other retrieval endpoints. Boundary markers: Absent. Capability inventory: Write access to catalog, enrollments, and reviews via POST and DELETE endpoints. Sanitization: Not explicitly defined in the provided instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 05:18 PM
Security Audit — agent-trust-hub — iblai-api-catalog