async-expert
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for building applications that consume data from external sources (e.g., APIs and data streams), creating a potential attack surface if the processed data is untrusted.
- Ingestion points: Coroutines like
fetch_user,fetch_page, andfetch_dataare designed to process external inputs. - Boundary markers: No explicit delimiters or boundary markers for untrusted data are used in the prompt interpolation examples.
- Capability inventory: The skill examples utilize network operations via
aiohttpandrequests, as well as file system access viafs.readFileandfs/promises. - Sanitization: The provided patterns do not demonstrate explicit sanitization or validation of input data before processing.
- [COMMAND_EXECUTION]: The workflow section suggests the use of shell commands such as
pytestandgrepfor code verification and environment auditing. These represent standard developer tool invocations within the local development environment.
Audit Metadata