appfolio-prod-checklist

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill serves as a security-focused checklist for developers, correctly emphasizing the use of secrets managers for sensitive credentials rather than insecure environment files.- [INDIRECT_PROMPT_INJECTION]: The validation script snippet contains points where external data is ingested from the AppFolio API via the /properties and /work_orders endpoints in SKILL.md. While no explicit boundary markers or sanitization logic are included, the script only utilizes the HTTP status code for logging, effectively neutralizing the risk of data-driven prompt injection. The skill's capabilities are scoped to the Bash, Write, and Edit tools.- [EXTERNAL_DOWNLOADS]: The skill links to official developer resources and engineering blogs on appfolio.com. These are recognized well-known services and do not constitute a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:40 AM
Security Audit — agent-trust-hub — appfolio-prod-checklist