hex-rate-limits

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines functions that process project parameters and include them in network requests to the Hex API, creating a vulnerability surface for indirect instructions.\n
  • Ingestion points: The params parameter in the hexRunWithRetry function within SKILL.md.\n
  • Boundary markers: The skill does not define delimiters or specific boundary instructions for the ingested data.\n
  • Capability inventory: The skill uses fetch to perform network POST operations to the Hex API.\n
  • Sanitization: The reference code lacks explicit sanitization or validation logic for the external project parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:48 AM
Security Audit — agent-trust-hub — hex-rate-limits