agentica-sdk
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documentation includes patterns for building agents that ingest external data (e.g., researcher queries, team notifications, and datasets), which could be leveraged for indirect prompt injection.
- Ingestion points: External data enters the agent context through arguments such as 'query', 'message', and 'dataset' in SKILL.md.
- Boundary markers: Example prompts and docstrings do not utilize explicit delimiters to isolate external content.
- Capability inventory: The skill environment supports 'Bash', 'Read', 'Write', and 'Edit' tools as specified in the frontmatter.
- Sanitization: Documentation examples do not demonstrate input sanitization or validation techniques.
- [REMOTE_CODE_EXECUTION]: The MCP integration example demonstrates the use of remote command execution.
- Evidence: The configuration shows the npx package runner executing 'mcp-remote' targeting the Tavily MCP endpoint.
- [EXTERNAL_DOWNLOADS]: The skill references downloading tool configurations from external services.
- Evidence: Fetches definitions from Tavily's official MCP service via npx.
Audit Metadata