cross-host-federation
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a multi-host communication mesh where an agent processes messages (claims, status, results) from external peers. This ingestion of data from the network represents a surface for indirect prompt injection. \n
- Ingestion points: Data enters the context via the
federation_bbs_synctool, which pulls remote message envelopes, and thefederation_bbs_watchtool, which monitors room messages. \n - Boundary markers: The skill documentation includes an explicit security warning instructing the agent to treat message content as data rather than commands and to validate it before performing side-effectful tasks. \n
- Capability inventory: The environment includes tools for network serving and synchronization, identity management, and a tool for file reading (
Read). \n - Sanitization: The architecture implements Ed25519 signature verification to ensure message origin and integrity from pinned peers, but the skill relies on manual validation of the payload content by the agent or user.
Audit Metadata