sinch-conversation-api
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle inbound message content from external users across various channels (SMS, WhatsApp, RCS, etc.), which introduces a surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context through inbound webhook payloads (specifically the
MESSAGE_INBOUNDtrigger) and when the agent retrieves message history using thescripts/common/list_messages.cjsscript. - Boundary markers: The
SKILL.mdfile contains robust boundary instructions, explicitly warning the agent that inbound content is untrusted data. It provides a specific example of an injection attempt ("ignore previous instructions...") to demonstrate what the agent must not obey. - Capability inventory: The skill's capabilities are limited to performing authenticated REST API requests via the Node.js
httpsmodule to the Sinch messaging platform. There are no patterns for executing shell commands or evaluating strings derived from inbound messages. - Sanitization: The skill mandates a safety policy that inbound content must not be executed, evaluated, or interpolated into prompts, serving as a strong instruction-level defense against malicious data processing.
Audit Metadata