taapi
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill transmits the
TAAPI_API_KEYas a plain-text query parameter (secret) in the request URL withintools/indicators.py(line 86) andtools/support_resistance.py(line 64). This practice exposes sensitive credentials to potential logging by network intermediaries and server-side logs. - [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch financial technical analysis data from
api.taapi.io. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from an external API, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: Data is fetched from
api.taapi.ioviaproxied_getandproxied_postintools/indicators.pyandtools/support_resistance.py. - Boundary markers: There are no explicit boundary markers or instructions provided to the agent to ignore potentially malicious content within the fetched data.
- Capability inventory: The skill possesses network communication capabilities and the ability to execute local Python modules.
- Sanitization: The skill does not validate or sanitize the JSON content returned from the external API before returning it to the agent context.
Audit Metadata