ai-wrapper-product

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill acts as an educational guide for AI product development, offering templates for building sustainable and secure AI wrappers.
  • [EXTERNAL_DOWNLOADS]: The JavaScript code snippets demonstrate the use of the @anthropic-ai/sdk package for interacting with large language models. This is the official SDK from Anthropic, a trusted organization.
  • [PROMPT_INJECTION]: The skill documents an attack surface for indirect prompt injection via user-supplied input and provides mitigation strategies:
  • Ingestion points: User-provided data enters the system through the userInput parameter in the generateContent and promptTemplates examples (SKILL.md).
  • Boundary markers: The templates utilize system prompts to define roles and constraints, separating them from user-provided content.
  • Capability inventory: The skill facilitates LLM interaction using the Anthropic SDK, which is the primary capability described.
  • Sanitization: The architecture diagram and code examples explicitly include validation logic (e.g., input length checks) and sanitization stages to process untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — ai-wrapper-product