secure-agent

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves asset names and configuration schemas from the Anypoint Exchange and API Manager. While this is necessary for its functionality, it creates an attack surface where maliciously named assets could influence agent behavior.
  • Ingestion points: Asset metadata from getAssetsSearch, gateway details from getGatewayTargets, and policy configurations from getExchangePolicyTemplates.
  • Boundary markers: No specific delimiters are used to wrap the platform-provided strings in prompts.
  • Capability inventory: The skill can create assets, deploy API instances, and apply policies.
  • Sanitization: The skill relies on platform-level security and does not implement client-side filtering of the retrieved metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 05:23 PM
Security Audit — agent-trust-hub — secure-agent