check-country-risk
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill proactively addresses potential injection risks by including a 'Content safety' section. It instructs the agent to treat all fields from the external API as data rather than instructions and specifically warns against acting on directive-like text found within responses.- [CREDENTIALS_UNSAFE]: The documentation contains an example API key ('wm_0123456789abcdef0123456789abcdef'). This is identified as a non-functional documentation placeholder. The provided bash example correctly demonstrates using an environment variable ($WM_API_KEY) rather than hardcoding actual credentials.
Audit Metadata