credential-recipe-research
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill uses a research tool to ingest content from external documentation websites. This introduces a surface for indirect prompt injection if an attacker-controlled page contains instructions intended to influence the agent. The skill provides functional mitigation by instructing the agent to extract specific technical fields exactly as documented and providing strict criteria for valid endpoints and URLs.
- [SAFE]: The skill incorporates safety best practices, explicitly instructing the agent to never include real secrets in the output and to select only side-effect-free, non-billable endpoints for credential verification probes.
Audit Metadata