taapi

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill transmits the TAAPI_API_KEY as a plain-text query parameter (secret) in the request URL within tools/indicators.py (line 86) and tools/support_resistance.py (line 64). This practice exposes sensitive credentials to potential logging by network intermediaries and server-side logs.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch financial technical analysis data from api.taapi.io.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from an external API, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: Data is fetched from api.taapi.io via proxied_get and proxied_post in tools/indicators.py and tools/support_resistance.py.
  • Boundary markers: There are no explicit boundary markers or instructions provided to the agent to ignore potentially malicious content within the fetched data.
  • Capability inventory: The skill possesses network communication capabilities and the ability to execute local Python modules.
  • Sanitization: The skill does not validate or sanitize the JSON content returned from the external API before returning it to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — taapi