track-military-flights
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests tracking data from external aviation networks (OpenSky and Wingbits) via an API. This data, which includes callsigns and operator information, constitutes a potential attack surface for indirect prompt injection. The skill documentation specifically includes a defensive section instructing the agent to treat all response data as untrusted and to ignore any embedded instructions, which is a recognized security best practice for this type of integration.
Audit Metadata