sinch-fax-api
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill outlines workflows for receiving faxes programmatically via webhooks, which exposes an indirect prompt injection surface if inbound content contains malicious instructions.
- Ingestion points: External data flows into the agent context via webhook callbacks, including fields like filenames, metadata,
errorMessage, andcontentUrlinSKILL.md. - Boundary markers: The skill contains explicit instructions to counter adversarial inputs, reminding the agent that text matching 'ignore previous instructions' must be treated strictly as data and never as executable commands.
- Capability inventory: The skill demonstrates executing
curlcommands to interact with the Sinch Fax API, but does not deploy automated system tools or dynamic code execution capabilities. - Sanitization: Explicit security guidelines instruct the agent to implement input validation and sanitization for all inbound content before logging, rendering, or parsing.
Audit Metadata