phone-verification

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it reads external SMS content.
  • Ingestion points: Reading SMS messages via read_phone_inbox in SKILL.md.
  • Boundary markers: None specified.
  • Capability inventory: No high-risk capabilities like file system or shell access are requested in this skill.
  • Sanitization: No sanitization of incoming SMS content is mentioned.
  • [SAFE]: The skill follows security best practices for credential management by instructing users to use dedicated tool calls (get_credential, store_credential) instead of hardcoding secrets or placing them in prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 07:36 AM
Security Audit — agent-trust-hub — phone-verification