igrantio-api-wallet-provider

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines workflows that ingest data from the iGrant.io API (e.g., wallet unit metadata and statistics) into the agent context. The absence of explicit boundary markers or sanitization instructions for this untrusted external data creates a surface for indirect prompt injection. 1. Ingestion points: API responses from endpoints like /v2/config/digital-wallet/openid/wallet-provider/wallet-units. 2. Boundary markers: None specified. 3. Capability inventory: The skill manages identity wallet configurations and credentials. 4. Sanitization: Not described in the documentation.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill handles sensitive authentication materials, specifically assertionToken and cryptographicSeed. It proactively identifies these as secrets and provides explicit instructions to prevent their leakage into logs, browser interfaces, or version control.
  • [SAFE]: All external URLs and API endpoints target igrant.io domains, which are controlled by the skill's authoring organization. These references are appropriate for the skill's intended administrative functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 03:58 PM
Security Audit — agent-trust-hub — igrantio-api-wallet-provider