netlify-forms
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is authored by the vendor (Netlify) and provides documentation for its own services. It explicitly warns against insecure practices like reading credentials from local CLI configuration files (~/Library/Preferences/netlify/config.json) or using undocumented API endpoints.\n- [EXTERNAL_DOWNLOADS]: All external links point to official Netlify documentation (docs.netlify.com) and API references (open-api.netlify.com), which are trusted vendor resources for this skill.\n- [INDIRECT_PROMPT_INJECTION]: The skill describes an attack surface involving the ingestion of external data (form submissions). This is the core functionality of the described service. The skill mitigates this risk by documenting platform-level sanitization (e.g., escaping tags) and recommending the use of built-in spam filters (Akismet) rather than custom implementations.\n
- Ingestion points: Reading submissions via the listFormSubmissions API operation in SKILL.md.\n
- Boundary markers: The documentation notes that submitted code is sanitized by the platform.\n
- Capability inventory: The skill allows the agent to read and page through form submissions via the Netlify API.\n
- Sanitization: Automatic escaping of executable code tags is provided by the Netlify platform.
Audit Metadata