sinch-numbers-api
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill performs network requests to official vendor endpoints such as
numbers.api.sinch.comand fetches authoritative documentation fromdevelopers.sinch.com. These domains are owned by the vendor and are used for legitimate API interaction and documentation referencing. - [COMMAND_EXECUTION]: The bundled script
scripts/get_numbers.cjsis designed to be executed via a shell to list and save active phone numbers. It utilizes standard Node.js libraries to perform authenticated API calls and writes the results to a user-specified local file viafs.writeFileSync. This behavior is transparent and consistent with the skill's management purpose. - [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential vulnerability surface related to inbound API callbacks. It proactively mitigates this risk by providing strict instructions to verify HMAC-SHA1 signatures and warns against interpolating callback body fields into prompts, shell commands, or evaluated code.
- [CREDENTIALS_UNSAFE]: The skill follows secure practices by instructing the agent to load sensitive information like
SINCH_KEY_SECRETandSINCH_ACCESS_TOKENfrom environment variables rather than hardcoding them in scripts or code examples.
Audit Metadata