run-service-scan-and-view-results

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is authored by the vendor (mulesoft) and utilizes legitimate platform URNs and APIs for its core discovery and reporting functionality. No hardcoded credentials, malicious persistence, or unauthorized data exfiltration patterns were identified.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from external platforms. 1. Ingestion points: Service names and descriptions retrieved via the getStagingAssetsByScanRunId operation in SKILL.md. 2. Boundary markers: No delimiters or specific safety instructions are present to prevent the agent from obeying instructions embedded in discovered service metadata. 3. Capability inventory: The skill is restricted to API-based discovery and metadata retrieval; it lacks capabilities for file system modification, command-line execution, or arbitrary code evaluation in the provided file. 4. Sanitization: No sanitization or verification of the content in the 'name' or 'description' fields is performed prior to presenting the data to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 01:23 AM
Security Audit — agent-trust-hub — run-service-scan-and-view-results