fairstack-smart-select
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected in the instructions or code examples.
- [COMMAND_EXECUTION]: The skill provides standard
curlcommand examples to demonstrate how to interact with the FairStack API. This is expected behavior for a technical documentation skill. - [DATA_EXPOSURE]: The documentation demonstrates safe practices by instructing users to use environment variables for API keys and providing placeholder values (
fs_live_...) instead of hardcoded credentials. - [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection, as it transmits user-supplied text to an external API to receive recommendations. This is the primary function of the skill and is handled following standard integration patterns.
- Ingestion points: User-provided descriptions are ingested via the
promptparameter in thePOST /v1/select-modelendpoint (SKILL.md). - Boundary markers: None explicitly defined in the skill documentation.
- Capability inventory: Performs network POST operations to
https://fairstack.ai(SKILL.md). - Sanitization: No sanitization or escaping logic is described in the integration examples.
Audit Metadata