skills/sinch/skills/sinch-numbers-api/Gen Agent Trust Hub

sinch-numbers-api

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to official vendor endpoints such as numbers.api.sinch.com and fetches authoritative documentation from developers.sinch.com. These domains are owned by the vendor and are used for legitimate API interaction and documentation referencing.
  • [COMMAND_EXECUTION]: The bundled script scripts/get_numbers.cjs is designed to be executed via a shell to list and save active phone numbers. It utilizes standard Node.js libraries to perform authenticated API calls and writes the results to a user-specified local file via fs.writeFileSync. This behavior is transparent and consistent with the skill's management purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential vulnerability surface related to inbound API callbacks. It proactively mitigates this risk by providing strict instructions to verify HMAC-SHA1 signatures and warns against interpolating callback body fields into prompts, shell commands, or evaluated code.
  • [CREDENTIALS_UNSAFE]: The skill follows secure practices by instructing the agent to load sensitive information like SINCH_KEY_SECRET and SINCH_ACCESS_TOKEN from environment variables rather than hardcoding them in scripts or code examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:41 PM
Security Audit — agent-trust-hub — sinch-numbers-api