sinch-conversation-api

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle inbound message content from external users across various channels (SMS, WhatsApp, RCS, etc.), which introduces a surface for indirect prompt injection.
  • Ingestion points: Untrusted data enters the agent context through inbound webhook payloads (specifically the MESSAGE_INBOUND trigger) and when the agent retrieves message history using the scripts/common/list_messages.cjs script.
  • Boundary markers: The SKILL.md file contains robust boundary instructions, explicitly warning the agent that inbound content is untrusted data. It provides a specific example of an injection attempt ("ignore previous instructions...") to demonstrate what the agent must not obey.
  • Capability inventory: The skill's capabilities are limited to performing authenticated REST API requests via the Node.js https module to the Sinch messaging platform. There are no patterns for executing shell commands or evaluating strings derived from inbound messages.
  • Sanitization: The skill mandates a safety policy that inbound content must not be executed, evaluated, or interpolated into prompts, serving as a strong instruction-level defense against malicious data processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:38 PM
Security Audit — agent-trust-hub — sinch-conversation-api