sinch-10dlc
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior or patterns were identified in the analyzed files. The skill provides clear instructions for interacting with the Sinch 10DLC Registration API and adheres to security best practices.
- [CREDENTIALS_UNSAFE]: The skill promotes secure development practices by instructing the agent to use environment variables for project IDs and secret keys. It also includes specific warnings against hardcoding credentials in code or logging sensitive registration data.
- [EXTERNAL_DOWNLOADS]: The skill allows the agent to fetch authoritative documentation from the vendor's official domain (
developers.sinch.com). This is categorized as safe as it targets a well-known service for the purpose of ensuring API schema accuracy and does not involve executing remote code. - [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface through Sinch API responses, specifically when polling for registration status and feedback. Because the data is retrieved from the vendor's authenticated API (us10dlc.numbers.api.sinch.com), the risk of indirect injection is considered safe within the context of the skill's primary functionality.
Audit Metadata