igrantio-dcql-multiple-statements

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of documentation and a configuration template. No executable code, scripts, or automated tools are provided.- [INDIRECT_PROMPT_INJECTION]: The skill defines a process for ingesting external data (bank statements) via the OpenID4VP protocol. While this represents a data ingestion surface, the skill is purely instructional and provides specific guidance on server-side validation. Ingestion points: The vpTokenResponse and presentation objects received from the wallet. Boundary markers: None explicitly defined in the JSON query template. Capability inventory: The skill contains no executable scripts, system-level capabilities, or network tools. Sanitization: Step 3 of the instructions recommends validating business rules, including instance counts and account number consistency.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 09:31 PM
Security Audit — agent-trust-hub — igrantio-dcql-multiple-statements