maxia
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides documentation for executing
curlcommands to interact with the marketplace API on the vendor's domain (maxiaworld.app).\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external AI services and marketplace responses, which represents a surface for indirect prompt injection where adversarial data could influence agent behavior.\n - Ingestion points: Data returned from API endpoints at
https://maxiaworld.app/api/public/*(SKILL.md).\n - Boundary markers: None are specified to separate external data from agent instructions.\n
- Capability inventory: Network communication capabilities via
curlto buy, sell, and execute marketplace services (SKILL.md).\n - Sanitization: No sanitization or filtering of API response content is documented.
Audit Metadata