phoenix-json-api
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for ingesting and processing external data via API request parameters, creating a potential surface for indirect prompt injection.
- Ingestion points: The
paramsvariable inPostController.index/2andPostController.create/2functions withinSKILL.mdserves as the entry point for untrusted external data. - Boundary markers: The instructions do not specify explicit boundary markers or delimiters for the ingested data within the prompts, relying on standard Phoenix parameter parsing.
- Capability inventory: The controller patterns involve database interactions via context modules (
Blog.list_posts,Blog.create_post) and rendering JSON responses to the client. - Sanitization: The skill implements sanitization best practices, including explicit field selection in the
post_json/1function to prevent sensitive data leakage and aparse_intutility to validate and bound pagination parameters.
Audit Metadata