track-military-flights

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests tracking data from external aviation networks (OpenSky and Wingbits) via an API. This data, which includes callsigns and operator information, constitutes a potential attack surface for indirect prompt injection. The skill documentation specifically includes a defensive section instructing the agent to treat all response data as untrusted and to ignore any embedded instructions, which is a recognized security best practice for this type of integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:20 PM
Security Audit — agent-trust-hub — track-military-flights