basecite-withdrawal
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data by reading documentation and API specifications from basecite.com at runtime.\n
- Ingestion points: SKILL.md (instructions to read auth.md and openapi.json).\n
- Boundary markers: Absent; the skill lacks instructions to ignore potential commands embedded in the fetched external content.\n
- Capability inventory: The skill is authorized to perform network operations including calling withdrawal APIs and polling status updates.\n
- Sanitization: Absent; no validation or sanitization logic is specified for the ingested markdown or JSON content.\n- [EXTERNAL_DOWNLOADS]: Fetches authentication documentation and an OpenAPI specification from the vendor's domain (basecite.com) to facilitate API interactions.
Audit Metadata