igrantio-dcapi-ios

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection (Category 8c
  • Tool output poisoning).
  • Ingestion points: The skill explicitly instructs the agent to fetch external documentation from https://docs.igrant.io/docs/openID4vc-send-verify-credentials-dcapi-ios/ in the 'Source of truth' section.
  • Boundary markers: No boundary markers or instructions to ignore embedded commands in the external data are provided.
  • Capability inventory: While this specific skill does not contain executable scripts, it is designed to work within the 'iGrant.io Organisation Wallet Suite' which includes frontend and backend verifier skills with active capabilities.
  • Sanitization: No sanitization or validation logic for the fetched external content is described. The instruction states 'the documentation wins
  • follow it', which potentially allows external content to override the agent's safe operating parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 09:31 PM
Security Audit — agent-trust-hub — igrantio-dcapi-ios