skills/scandit/skills/sparkscan-web/Gen Agent Trust Hub

sparkscan-web

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze project metadata (like package.json) and source code to assist with SDK integration and migration. This creates a surface for indirect prompt injection if project files contain malicious instructions, a common characteristic of development-focused skills. \n
  • Ingestion points: References to checking package.json, lock files, and application source code in integration.md, react.md, and migration.md. \n
  • Boundary markers: No specific delimiters are used to wrap ingested project content. \n
  • Capability inventory: File system read operations and proposed modifications via agent tools. \n
  • Sanitization: Content from ingested files is processed without specific sanitization filters. \n- [PROMPT_INJECTION]: The skill contains instructions for the agent to prioritize the provided reference materials over training data to ensure API accuracy. This is a functional constraint to prevent hallucinations and is not an attempt to bypass safety guardrails. \n- [CREDENTIALS_UNSAFE]: The skill uses the placeholder -- ENTER YOUR SCANDIT LICENSE KEY HERE -- across several files to show where users should input their API keys. This is a safe documentation pattern. \n- [EXTERNAL_DOWNLOADS]: References are made to official Scandit documentation and GitHub repositories. These are trusted vendor sources used for legitimate technical reference.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:33 PM
Security Audit — agent-trust-hub — sparkscan-web