sinch-verification-api

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acknowledges and addresses the risks of processing untrusted external data.
  • Ingestion points: Data ingested through webhook callbacks (VerificationRequestEvent, VerificationResultEvent) and external documentation fetched from the vendor domain (developers.sinch.com).
  • Boundary markers: The instructions explicitly warn the agent to treat callback fields as untrusted and to prioritize canonical documentation over skill summaries.
  • Capability inventory: The skill facilitates code generation for network requests (curl, SDKs) and data processing.
  • Sanitization: The Security section specifically mandates the sanitization of fields like identity, cli, and custom before they are used in logs, UI rendering, or further command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 01:06 PM
Security Audit — agent-trust-hub — sinch-verification-api