spring-ai
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [SAFE]: The skill provides documentation and implementation patterns for the Spring AI framework. No malicious behaviors or security risks were identified in the analyzed reference material.
- [DATA_EXFILTRATION]: Documentation includes security warnings regarding prompt and completion logging features (
log-prompt,log-completion), correctly identifying their potential risk of exposing sensitive user data in application traces. - [PROMPT_INJECTION]: The skill includes defensive instructions for implementing tool calling, advising that tool descriptions should be specific and hardened against injection, and that AI-generated tool calls should be treated as untrusted input.
- [EXTERNAL_DOWNLOADS]: Provides configuration examples for the Model Context Protocol (MCP) using well-known services, such as the Brave Search MCP server from Anthropic. These references are documented neutrally as standard configuration patterns.
Audit Metadata