sinch-sdks
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or security vulnerabilities were identified in the skill instructions or referenced scripts.
- [EXTERNAL_DOWNLOADS]: The skill references standard package installations for Node.js (@sinch/sdk-core), Python (sinch), Java (sinch-sdk-java), and .NET (Sinch) from official registries. These downloads target official vendor-owned libraries.
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch external documentation from developers.sinch.com. While this is an ingestion point for external data, it targets an authoritative and trusted source.
- Ingestion points: Documentation links at developers.sinch.com (referenced in SKILL.md).
- Boundary markers: SKILL.md includes a 'Source of Truth' section that provides explicit rules for the agent on how to handle and prioritize this external data.
- Capability inventory: No dangerous tool capabilities such as arbitrary command execution, file system writes, or network exfiltration tools are used in this skill.
- Sanitization: The skill does not implement specific sanitization or filtering of the external documentation content.
Audit Metadata