rootdata
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves data from an external API (RootData) which includes project descriptions, one-liners, and biographical metadata. This untrusted content could potentially contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Content is fetched from api.rootdata.com via functions in exports.py such as rd_search and rd_project_detail.
- Boundary markers: The skill does not wrap the external content in specific delimiters or provide warnings to the agent before returning the data.
- Capability inventory: The skill is restricted to making network requests to the authorized RootData API and writing cost logs to a local directory; it lacks dangerous execution capabilities like eval() or subprocess.run().
- Sanitization: No filtering or sanitization is performed on the data returned from the API.
Audit Metadata