igrantio-dcapi-android
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The workflow correctly implements replay protection via 'expectedOrigins' and utilizes standard browser-based verification protocols.
- [SAFE]: All external references and documentation URLs belong to the author's verified domain (igrant.io), and no unauthorized downloads or network exfiltration patterns are present.
- [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection as it processes external credential data.
- Ingestion points: SKILL.md (Workflow step 5: decoding 'vpTokenResponse').
- Boundary markers: Not present.
- Capability inventory: None (no command execution or sensitive file access is defined in this documentation).
- Sanitization: Not explicitly described for the parsed response fields.
Audit Metadata