lucidchart-prod-checklist
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches official integration requirements, authentication scopes, and service status updates from Lucid's developer and status domains (
developer.lucid.co,status.lucid.co). - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests untrusted data from the local repository and external documentation during the readiness review.
- Ingestion points: Reads repository files via
Read,Glob, andGrep; fetches external web content viaWebFetch. - Boundary markers: None explicitly defined for ingested content.
- Capability inventory: Uses
WriteandEditto generate local gate receipts and documentation fixes. - Sanitization: No specific sanitization or filtering of external content is defined, though instructions require redacting logs and protecting secrets.
Audit Metadata