currency-converter
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external currency data fetched from APIs, creating a surface where malicious instructions could potentially influence agent behavior.
- Ingestion points: External currency and historical rate data retrieved via
sandbase_call_toolusing thestrale_currency_convertandstrale_exchange_ratetools. - Boundary markers: There are no explicit delimiters or instructions provided in SKILL.md to isolate tool outputs from system instructions.
- Capability inventory: The skill possesses network research capabilities via the
sandbase_call_toolgateway. - Sanitization: No input validation or output sanitization is mentioned for the data returned from the conversion tools before it is synthesized for the user.
Audit Metadata