agentica-server

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an architecture for an agent server that processes external inference requests, creating a potential surface for indirect prompt injection.
  • Ingestion points: External data enters the system via the INFERENCE_ENDPOINT_URL (Agentica Server) and the S_M_BASE_URL (SDK Client).
  • Boundary markers: The instructions do not specify any delimiters or boundary markers to isolate untrusted data from the agent's system instructions.
  • Capability inventory: The skill's configuration enables high-privilege tools including Bash and Read (file system access), which could be exploited if malicious instructions are processed.
  • Sanitization: No sanitization or validation mechanisms are documented for the incoming inference data stream.
  • [PROMPT_INJECTION]: The documentation includes a specific instruction intended to override default agent behavior to prevent hallucinations.
  • Evidence: The section "4. Agent claims success but didn't do task" suggests adding the prompt: CRITICAL: Use ACTUAL tools. Never DESCRIBE using tools.
  • Context: While intended to improve reliability, the use of the CRITICAL marker to enforce behavior is a common pattern used in prompt injection to override an agent's standard operating logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — agentica-server