hex-rate-limits
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines functions that process project parameters and include them in network requests to the Hex API, creating a vulnerability surface for indirect instructions.\n
- Ingestion points: The
paramsparameter in thehexRunWithRetryfunction withinSKILL.md.\n - Boundary markers: The skill does not define delimiters or specific boundary instructions for the ingested data.\n
- Capability inventory: The skill uses
fetchto perform networkPOSToperations to the Hex API.\n - Sanitization: The reference code lacks explicit sanitization or validation logic for the external project parameters.
Audit Metadata