appfolio-hello-world
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external AppFolio API endpoints.
- Ingestion points: Data is fetched from the
/propertiesand/tenantsendpoints as shown inSKILL.md. - Boundary markers: The instructions lack explicit boundary markers or delimiters to prevent the agent from interpreting data returned by the API as instructions.
- Capability inventory: The skill is granted access to high-privilege tools including
Write,Edit, andBash, which increases the potential impact if malicious data from the API influences the agent's behavior. - Sanitization: There is no evidence of data sanitization or validation performed on the API responses before they are presented to the agent context.
Audit Metadata