agentica-server
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines an architecture for an agent server that processes external inference requests, creating a potential surface for indirect prompt injection.
- Ingestion points: External data enters the system via the
INFERENCE_ENDPOINT_URL(Agentica Server) and theS_M_BASE_URL(SDK Client). - Boundary markers: The instructions do not specify any delimiters or boundary markers to isolate untrusted data from the agent's system instructions.
- Capability inventory: The skill's configuration enables high-privilege tools including
BashandRead(file system access), which could be exploited if malicious instructions are processed. - Sanitization: No sanitization or validation mechanisms are documented for the incoming inference data stream.
- [PROMPT_INJECTION]: The documentation includes a specific instruction intended to override default agent behavior to prevent hallucinations.
- Evidence: The section "4. Agent claims success but didn't do task" suggests adding the prompt:
CRITICAL: Use ACTUAL tools. Never DESCRIBE using tools. - Context: While intended to improve reliability, the use of the
CRITICALmarker to enforce behavior is a common pattern used in prompt injection to override an agent's standard operating logic.
Audit Metadata