incremental-fetch

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is instructional and contains no executable code or automated scripts. Analysis of SKILL.md and patterns.md confirms the content is educational and lacks malicious patterns or obfuscation.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for ingesting data from untrusted external APIs as documented in references/patterns.md. 1. Ingestion points: External API responses fetched via the fetch_for_asset logic. 2. Boundary markers: None present in the provided templates. 3. Capability inventory: Includes network fetching (requests.get) and database writes (SQL INSERT). 4. Sanitization: No explicit sanitization or validation of the ingested data is included in the code samples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — incremental-fetch