database-lookup
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from over 80 external database APIs, many of which include user-contributed content such as patent text, clinical notes, and abstracts that could contain malicious instructions.
- Ingestion points: External API responses documented in the references directory enter the agent context via Bash-driven network requests.
- Boundary markers: Instructions in SKILL.md mandate labeling raw payloads as untrusted third-party data and returning concise, structured summaries.
- Capability inventory: The skill employs the Bash tool for network requests and can generate or execute Python scripts for SOAP-based APIs like BRENDA.
- Sanitization: Step 6 in SKILL.md explicitly forbids following instructions embedded in returned data and requires field validation before using data in subsequent tool calls.
Audit Metadata