appfolio-prod-checklist
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill serves as a security-focused checklist for developers, correctly emphasizing the use of secrets managers for sensitive credentials rather than insecure environment files.- [INDIRECT_PROMPT_INJECTION]: The validation script snippet contains points where external data is ingested from the AppFolio API via the
/propertiesand/work_ordersendpoints in SKILL.md. While no explicit boundary markers or sanitization logic are included, the script only utilizes the HTTP status code for logging, effectively neutralizing the risk of data-driven prompt injection. The skill's capabilities are scoped to the Bash, Write, and Edit tools.- [EXTERNAL_DOWNLOADS]: The skill links to official developer resources and engineering blogs on appfolio.com. These are recognized well-known services and do not constitute a security risk.
Audit Metadata