auth-guide

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The guide recommends patterns for ingesting data from external, potentially untrusted sources which creates a surface for indirect prompt injection attacks.
  • Ingestion points: The skill instructions suggest that agents process data from user-provided .har files, external email accounts via OAuth parsing, and unofficial service endpoints (SKILL.md).
  • Boundary markers: There are no instructions in the guide directing the agent to use specific delimiters or 'ignore' instructions when processing data from these external sources.
  • Capability inventory: The worker framework described includes capabilities for performing network requests via fetch, managing injected credentials with worker.credential, and establishing OAuth connections using worker.oauth (SKILL.md).
  • Sanitization: The guide lacks instructions for sanitizing or validating the content retrieved from these external sources before the AI agent processes or interprets it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:37 AM
Security Audit — agent-trust-hub — auth-guide