navan-data-handling

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for ingesting untrusted data from the Navan API (v1/bookings) which may contain malicious instructions. \n- Ingestion points: API response data processed in SKILL.md snippets. \n- Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore embedded instructions in the fetched data. \n- Capability inventory: The skill utilizes fetch, requests, and has access to Bash (npm, curl, pip) for processing data. \n- Sanitization: No evidence of data sanitization or validation was found in the provided processing scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 12:37 PM
Security Audit — agent-trust-hub — navan-data-handling