basecite-developer-integration

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill provides documentation and security guidelines for developers. It emphasizes server-side credential storage and the use of idempotency keys for state-changing requests.- [INDIRECT_PROMPT_INJECTION]: The skill mentions processing customer-submitted material and AI context, which identifies a vulnerability surface.
  • Ingestion points: BaseCite API uploads and derived AI context (SKILL.md).
  • Boundary markers: The skill instructions include a warning (Step 5) to treat context as customer-submitted material rather than verified truth.
  • Capability inventory: None; the skill contains only markdown instructions and no executable scripts or tool definitions.
  • Sanitization: Instructions recommend treating incoming data as untrusted content.- [EXTERNAL_DOWNLOADS]: The skill references the official BaseCite API documentation URL (https://api.basecite.com/api/v1/ai/openapi.json) for implementation guidance.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 06:57 PM
Security Audit — agent-trust-hub — basecite-developer-integration