basecite-withdrawal

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data by reading documentation and API specifications from basecite.com at runtime.\n
  • Ingestion points: SKILL.md (instructions to read auth.md and openapi.json).\n
  • Boundary markers: Absent; the skill lacks instructions to ignore potential commands embedded in the fetched external content.\n
  • Capability inventory: The skill is authorized to perform network operations including calling withdrawal APIs and polling status updates.\n
  • Sanitization: Absent; no validation or sanitization logic is specified for the ingested markdown or JSON content.\n- [EXTERNAL_DOWNLOADS]: Fetches authentication documentation and an OpenAPI specification from the vendor's domain (basecite.com) to facilitate API interactions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 06:56 PM
Security Audit — agent-trust-hub — basecite-withdrawal