integrate-api-client

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a robust defense-in-depth strategy against indirect prompt injection. It defines a mandatory 'Builder' layer to sanitize untrusted API responses before they reach the agent context or application logic.
  • Ingestion points: External API responses processed by the Client layer in generated Ruby code.
  • Boundary markers: Explicit instructions to treat third-party payloads as untrusted and ignore embedded directives.
  • Capability inventory: Code generation for network requests and data processing.
  • Sanitization: Use of attribute allowlisting (ATTRIBUTES) and the removal of instruction-like keys such as 'prompt', 'system', and 'instructions'.
  • [PROMPT_INJECTION]: Mentions of instruction overrides in the skill text are used defensively, instructing the agent to ignore malicious commands embedded within untrusted third-party data.
  • [SAFE]: The skill demonstrates standard development practices for Ruby applications, including secure credential management using environment variables and synthetic fixtures for testing. References to the 'igmarin/rails-agent-skills' repository are consistent with the author and represent legitimate vendor resources. No malicious patterns were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:23 PM
Security Audit — agent-trust-hub — integrate-api-client