skills/scandit/skills/id-capture-kmp/Gen Agent Trust Hub

id-capture-kmp

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains strong directives such as 'Critical: Do Not Trust Internal Knowledge' and 'Forbidden APIs'. These are functional constraints designed to prevent the model from hallucinating incorrect API calls based on outdated training data, ensuring the generated code is accurate for the specific KMP SDK. These instructions do not attempt to bypass safety guardrails or maliciously override agent behavior.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a vulnerability surface by instructing the agent to fetch and verify APIs against Scandit's official documentation at docs.scandit.com. This is a standard documentation lookup pattern for technical skills. The ingestion is limited to the vendor's official domain, and the instructions emphasize providing direct answers followed by official reference links for user verification.
  • Ingestion points: User queries regarding SDK integration and external documentation links to docs.scandit.com and ssl.scandit.com.
  • Boundary markers: The instructions explicitly command the agent to verify all APIs against the provided references and to provide the user with the corresponding source link.
  • Capability inventory: Code generation based on documentation and provided snippets; no dynamic script execution capabilities are included in the skill.
  • Sanitization: Standard LLM output filtering applies; the skill does not define custom sanitization logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 07:18 AM
Security Audit — agent-trust-hub — id-capture-kmp