syndly-setup

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external URLs (RSS feeds or sitemaps) provided by the user, creating a surface for indirect prompt injection where malicious content from the source could influence agent behavior. \n
  • Ingestion points: The agent accepts a user-provided url during the add_source workflow in SKILL.md. \n
  • Boundary markers: The instructions explicitly require the agent to show the exact input and receive explicit human approval before calling the add_source tool and before writing local files. \n
  • Capability inventory: The agent has the ability to write to the local filesystem (./.syndly/) and perform API publishing actions through the add_source tool. \n
  • Sanitization: The instructions do not specify any validation or sanitization requirements for the content retrieved from or represented by the provided URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 08:24 AM
Security Audit — agent-trust-hub — syndly-setup