incremental-fetch
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is instructional and contains no executable code or automated scripts. Analysis of SKILL.md and patterns.md confirms the content is educational and lacks malicious patterns or obfuscation.
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for ingesting data from untrusted external APIs as documented in references/patterns.md. 1. Ingestion points: External API responses fetched via the fetch_for_asset logic. 2. Boundary markers: None present in the provided templates. 3. Capability inventory: Includes network fetching (requests.get) and database writes (SQL INSERT). 4. Sanitization: No explicit sanitization or validation of the ingested data is included in the code samples.
Audit Metadata