appfolio-hello-world

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external AppFolio API endpoints.
  • Ingestion points: Data is fetched from the /properties and /tenants endpoints as shown in SKILL.md.
  • Boundary markers: The instructions lack explicit boundary markers or delimiters to prevent the agent from interpreting data returned by the API as instructions.
  • Capability inventory: The skill is granted access to high-privilege tools including Write, Edit, and Bash, which increases the potential impact if malicious data from the API influences the agent's behavior.
  • Sanitization: There is no evidence of data sanitization or validation performed on the API responses before they are presented to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:40 AM
Security Audit — agent-trust-hub — appfolio-hello-world