agentica-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documentation includes patterns for building agents that ingest external data (e.g., researcher queries, team notifications, and datasets), which could be leveraged for indirect prompt injection.
  • Ingestion points: External data enters the agent context through arguments such as 'query', 'message', and 'dataset' in SKILL.md.
  • Boundary markers: Example prompts and docstrings do not utilize explicit delimiters to isolate external content.
  • Capability inventory: The skill environment supports 'Bash', 'Read', 'Write', and 'Edit' tools as specified in the frontmatter.
  • Sanitization: Documentation examples do not demonstrate input sanitization or validation techniques.
  • [REMOTE_CODE_EXECUTION]: The MCP integration example demonstrates the use of remote command execution.
  • Evidence: The configuration shows the npx package runner executing 'mcp-remote' targeting the Tavily MCP endpoint.
  • [EXTERNAL_DOWNLOADS]: The skill references downloading tool configurations from external services.
  • Evidence: Fetches definitions from Tavily's official MCP service via npx.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — agentica-sdk