basecite-developer-integration
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill provides documentation and security guidelines for developers. It emphasizes server-side credential storage and the use of idempotency keys for state-changing requests.- [INDIRECT_PROMPT_INJECTION]: The skill mentions processing customer-submitted material and AI context, which identifies a vulnerability surface.
- Ingestion points: BaseCite API uploads and derived AI context (SKILL.md).
- Boundary markers: The skill instructions include a warning (Step 5) to treat context as customer-submitted material rather than verified truth.
- Capability inventory: None; the skill contains only markdown instructions and no executable scripts or tool definitions.
- Sanitization: Instructions recommend treating incoming data as untrusted content.- [EXTERNAL_DOWNLOADS]: The skill references the official BaseCite API documentation URL (https://api.basecite.com/api/v1/ai/openapi.json) for implementation guidance.
Audit Metadata