check-chokepoint-status

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acknowledges the risk of malicious instructions being embedded in data retrieved from the World Monitor API and provides appropriate guidance.
  • Ingestion points: Data is ingested from the external worldmonitor.app API as described in SKILL.md.
  • Boundary markers: The skill includes a dedicated 'Content safety' section that explicitly instructs the agent to treat response fields as data, not instructions, and to disregard directive-like text such as 'ignore previous instructions'.
  • Capability inventory: The skill is limited to performing network GET requests to fetch data; it does not perform file writes or local command execution based on the API response.
  • Sanitization: The skill employs prompt-based defensive instructions to ensure the agent maintains its original role despite potential adversarial content in the data feed.
  • [SAFE]: The skill follows secure development practices by using a placeholder API key for documentation and recommending the use of environment variables for production secrets. The network operations are restricted to the service's legitimate API domain.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:20 PM
Security Audit — agent-trust-hub — check-chokepoint-status