lucidchart-debug-bundle

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted content from local project files and external Lucid API responses, creating an attack surface where embedded instructions could influence the agent's behavior. * Ingestion points: The skill reads local artifacts using Read, Glob, and Grep tools and fetches remote content via WebFetch. * Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the content being processed. * Capability inventory: The skill possesses Write and Edit capabilities to create bundles and WebFetch for network access. * Sanitization: While the instructions mandate rigorous redaction of PII and credentials, they do not specifically address the sanitization of prompt-based instructions within data.
  • [EXTERNAL_DOWNLOADS]: Fetches current API contracts and service health evidence from Lucid's official developer and status domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:11 AM
Security Audit — agent-trust-hub — lucidchart-debug-bundle