auth-guide
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The guide recommends patterns for ingesting data from external, potentially untrusted sources which creates a surface for indirect prompt injection attacks.
- Ingestion points: The skill instructions suggest that agents process data from user-provided .har files, external email accounts via OAuth parsing, and unofficial service endpoints (SKILL.md).
- Boundary markers: There are no instructions in the guide directing the agent to use specific delimiters or 'ignore' instructions when processing data from these external sources.
- Capability inventory: The worker framework described includes capabilities for performing network requests via fetch, managing injected credentials with worker.credential, and establishing OAuth connections using worker.oauth (SKILL.md).
- Sanitization: The guide lacks instructions for sanitizing or validating the content retrieved from these external sources before the AI agent processes or interprets it.
Audit Metadata