planet-bulk-download

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a pipeline that ingests external data from local manifests and remote API responses, creating an indirect prompt injection surface where maliciously crafted external content could influence agent behavior or trigger unintended network requests.\n
  • Ingestion points: Input manifest files (manifest.jsonl) and Planet API response fields (signed URLs).\n
  • Boundary markers: Absent. No delimiters or warnings are used to separate untrusted data from instructions.\n
  • Capability inventory: The pipeline includes significant network capabilities (httpx, Planet SDK, rasterio vsicurl) and local file write capabilities.\n
  • Sanitization: Absent. The instructions do not include validation for URL schemes, file paths, or metadata content before they are processed by tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 07:53 PM
Security Audit — agent-trust-hub — planet-bulk-download