skills/sinch/skills/sinch-porting-api/Gen Agent Trust Hub

sinch-porting-api

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions identify a potential attack surface where the agent processes inbound webhook payloads from the Porting API. It correctly advises treating these payloads as untrusted and sanitizing fields before use in logging or prompt interpolation. * Ingestion points: Inbound port-in webhook payloads. * Boundary markers: Explicit advice to treat payloads as untrusted. * Capability inventory: Tool-based execution of HTTP requests (Agent capability). * Sanitization: Explicit instructions to sanitize fields before interpolation.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill handles sensitive personal information (PII) including subscriber names, addresses, and port-out PINs. However, it follows security best practices by mandating the use of environment variables for credentials and advising against logging full payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:40 PM
Security Audit — agent-trust-hub — sinch-porting-api