serpapi-debug-bundle
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data including search archive records and local logs, creating a potential surface for indirect prompt injection.
- Ingestion points: Data enters the context through log analysis via
ReadandGreptools, as well as fetching remote search records. - Capability inventory: The skill uses
WebFetchfor network connectivity andWriteorEditfor generating debug reports. - Boundary markers: Clear instructions mandate 'automated and human redaction checks' and 'data classification and approval' before bundle creation.
- Sanitization: The authentication section specifically requires removing API keys, email addresses, and sensitive query values from the final output.
Audit Metadata