check-chokepoint-status
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acknowledges the risk of malicious instructions being embedded in data retrieved from the World Monitor API and provides appropriate guidance.
- Ingestion points: Data is ingested from the external
worldmonitor.appAPI as described inSKILL.md. - Boundary markers: The skill includes a dedicated 'Content safety' section that explicitly instructs the agent to treat response fields as data, not instructions, and to disregard directive-like text such as 'ignore previous instructions'.
- Capability inventory: The skill is limited to performing network GET requests to fetch data; it does not perform file writes or local command execution based on the API response.
- Sanitization: The skill employs prompt-based defensive instructions to ensure the agent maintains its original role despite potential adversarial content in the data feed.
- [SAFE]: The skill follows secure development practices by using a placeholder API key for documentation and recommending the use of environment variables for production secrets. The network operations are restricted to the service's legitimate API domain.
Audit Metadata