serpapi-deploy-integration

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external deployment configurations, diffs, and dependency locks which are untrusted ingestion points. However, it incorporates robust security practices to mitigate injection risks.
  • Ingestion points: The skill reviews deployment diffs, dependency locks, and route exposure details (SKILL.md).
  • Boundary markers: Instructions explicitly require the use of an input allowlist and output projection to constrain data flow and prevent accidental instruction execution.
  • Capability inventory: The skill utilizes tools like Write and Edit for configuration management and WebFetch for contract verification.
  • Sanitization: It includes detailed error handling for sensitive data leakage, such as blocking keys in assets and removing account facts from health endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 08:40 AM
Security Audit — agent-trust-hub — serpapi-deploy-integration