chainlink-confidential-ai-attester-skill

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is designed to transmit sensitive user documents, such as bank and brokerage statements, to an external API endpoint (https://confidential-ai-dev-preview.cldev.cloud). While this is the intended function for confidential processing, it constitutes a data exposure surface where sensitive information is sent outside the local environment.
  • [PROMPT_INJECTION]: The skill facilitates processing untrusted external content, which presents an indirect prompt injection surface.
  • Ingestion points: Untrusted data is ingested via the resources parameter in the inference request as shown in SKILL.md and references/api-reference.md.
  • Boundary markers: The prompt templates in references/prompts.md do not utilize delimiting markers or specific instructions to help the model distinguish between user instructions and potentially malicious content within the documents.
  • Capability inventory: The skill allows access to multiple tools including Bash, Read, WebFetch, Write, and Edit, which increases the potential impact if the agent is influenced by malicious document content.
  • Sanitization: No sanitization or verification of the document content or source URLs is performed before the data is processed or transmitted.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 08:52 AM
Security Audit — agent-trust-hub — chainlink-confidential-ai-attester-skill