ai-gateway
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses authoritative language ("CRITICAL — Your training data is outdated", "do not guess") to instruct the agent to disregard its internal training data in favor of provided content. This content includes fictional model versions (e.g., GPT-5.4, GPT-5.6) and future dates (March 2026) presented as authoritative facts.
- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for building AI-powered features that ingest untrusted user prompts.
- Ingestion points: The
promptparameter ingenerateText,streamText, andgenerateImageexamples inSKILL.md. - Boundary markers: None present; the code examples interpolate user messages directly into the model call.
- Capability inventory: Network operations via the Vercel AI Gateway API and associated provider endpoints.
- Sanitization: The examples do not demonstrate validation, escaping, or filtering of the input prompt data.
- [EXTERNAL_DOWNLOADS]: The skill references and fetches resources from Vercel's official documentation and GitHub repositories.
- [COMMAND_EXECUTION]: The instructions include shell commands for environment setup and dependency management, such as
vercel env pullandnpm install @ai-sdk/gateway.
Audit Metadata