skills/sinch/skills/sinch-fax-api/Gen Agent Trust Hub

sinch-fax-api

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill outlines workflows for receiving faxes programmatically via webhooks, which exposes an indirect prompt injection surface if inbound content contains malicious instructions.
  • Ingestion points: External data flows into the agent context via webhook callbacks, including fields like filenames, metadata, errorMessage, and contentUrl in SKILL.md.
  • Boundary markers: The skill contains explicit instructions to counter adversarial inputs, reminding the agent that text matching 'ignore previous instructions' must be treated strictly as data and never as executable commands.
  • Capability inventory: The skill demonstrates executing curl commands to interact with the Sinch Fax API, but does not deploy automated system tools or dynamic code execution capabilities.
  • Sanitization: Explicit security guidelines instruct the agent to implement input validation and sanitization for all inbound content before logging, rendering, or parsing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:37 PM
Security Audit — agent-trust-hub — sinch-fax-api