grant-access

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input (usernames, emails, and service names) to perform privileged actions including sending tailnet invites and modifying Access Control Lists (ACLs). This vulnerability surface allows for potential manipulation of security policies if the agent blindly trusts the input provided during conversation. The skill includes manual verification steps (e.g., "Verify from both sides", "Read the live policy before proposing any change") which serve as mitigations to ensure configuration integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 05:01 PM
Security Audit — agent-trust-hub — grant-access