ai-wrapper-product
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill acts as an educational guide for AI product development, offering templates for building sustainable and secure AI wrappers.
- [EXTERNAL_DOWNLOADS]: The JavaScript code snippets demonstrate the use of the
@anthropic-ai/sdkpackage for interacting with large language models. This is the official SDK from Anthropic, a trusted organization. - [PROMPT_INJECTION]: The skill documents an attack surface for indirect prompt injection via user-supplied input and provides mitigation strategies:
- Ingestion points: User-provided data enters the system through the
userInputparameter in thegenerateContentandpromptTemplatesexamples (SKILL.md). - Boundary markers: The templates utilize system prompts to define roles and constraints, separating them from user-provided content.
- Capability inventory: The skill facilitates LLM interaction using the Anthropic SDK, which is the primary capability described.
- Sanitization: The architecture diagram and code examples explicitly include validation logic (e.g., input length checks) and sanitization stages to process untrusted data.
Audit Metadata