igrantio-dcapi-ios
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection (Category 8c
- Tool output poisoning).
- Ingestion points: The skill explicitly instructs the agent to fetch external documentation from
https://docs.igrant.io/docs/openID4vc-send-verify-credentials-dcapi-ios/in the 'Source of truth' section. - Boundary markers: No boundary markers or instructions to ignore embedded commands in the external data are provided.
- Capability inventory: While this specific skill does not contain executable scripts, it is designed to work within the 'iGrant.io Organisation Wallet Suite' which includes frontend and backend verifier skills with active capabilities.
- Sanitization: No sanitization or validation logic for the fetched external content is described. The instruction states 'the documentation wins
- follow it', which potentially allows external content to override the agent's safe operating parameters.
Audit Metadata