serpapi-debug-bundle

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data including search archive records and local logs, creating a potential surface for indirect prompt injection.
  • Ingestion points: Data enters the context through log analysis via Read and Grep tools, as well as fetching remote search records.
  • Capability inventory: The skill uses WebFetch for network connectivity and Write or Edit for generating debug reports.
  • Boundary markers: Clear instructions mandate 'automated and human redaction checks' and 'data classification and approval' before bundle creation.
  • Sanitization: The authentication section specifically requires removing API keys, email addresses, and sensitive query values from the final output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 08:40 AM
Security Audit — agent-trust-hub — serpapi-debug-bundle