igrantio-dcapi-android

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The workflow correctly implements replay protection via 'expectedOrigins' and utilizes standard browser-based verification protocols.
  • [SAFE]: All external references and documentation URLs belong to the author's verified domain (igrant.io), and no unauthorized downloads or network exfiltration patterns are present.
  • [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection as it processes external credential data.
  • Ingestion points: SKILL.md (Workflow step 5: decoding 'vpTokenResponse').
  • Boundary markers: Not present.
  • Capability inventory: None (no command execution or sensitive file access is defined in this documentation).
  • Sanitization: Not explicitly described for the parsed response fields.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 09:32 PM
Security Audit — agent-trust-hub — igrantio-dcapi-android