sinch-sms
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive guidance on managing credentials using environment variables rather than hardcoding them.
- [SAFE]: The skill explicitly warns about the risks of indirect prompt injection from inbound SMS messages, instructing the agent to treat such content as untrusted data rather than instructions.
- [SAFE]: Network operations and documentation links are restricted to official vendor domains (sinch.com) or well-known development resources.
- [SAFE]: Deterministic detector flags for prompt injection were found to be false positives; the identified phrases were part of legitimate security instructions to the agent to avoid obeying user-provided data as commands.
Audit Metadata