protocolsio-integration
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes structured and unstructured data from the protocols.io API, which may contain instructions embedded by external authors.\n
- Ingestion points: Protocol metadata, step text, and discussion comments are ingested through
scripts/protocols_read.pyand processed viascripts/validate_protocol_json.py.\n - Boundary markers: The skill's instructions in
SKILL.mdandreferences/discussions.mdexplicitly mandate treating all remote content as untrusted data and provide guidelines for neutralizing links and mentions.\n - Capability inventory: The skill performs idempotent network GET requests and writes bounded JSON and PDF data to the local filesystem. It lacks capabilities for dynamic code evaluation or arbitrary shell command execution.\n
- Sanitization: All remote data is processed through
scripts/_common.pyusingsanitize_untrustedto redact sensitive keys andclean_textto remove control characters and enforce length limits.\n- [EXTERNAL_DOWNLOADS]: The skill facilitates data retrieval from the official protocols.io domain.\n - Network access is restricted to HTTPS requests targeting
www.protocols.ioand validated organization subdomains on port 443.\n - The implementation uses a custom transport that explicitly disables HTTP redirects and proxy discovery to prevent credential leakage.\n
- All network operations are gated behind an explicit
--executeflag and capped by response size limits.\n- [COMMAND_EXECUTION]: The skill utilizes the Python interpreter to run its bundled helper scripts for data validation and request planning.\n - Script execution is limited to the skill's own source code using the standard library, with no invocation of external binaries or shell environments.
Audit Metadata