object-buttons
Pass
Audited by Gen Agent Trust Hub on Apr 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines legitimate configuration patterns for the Steedos platform. The examples provided for AJAX calls, navigation, and logic are consistent with official platform documentation.
- [PROMPT_INJECTION]: The skill describes a surface for indirect prompt injection through the processing of .button.yml configuration files.
- Ingestion points: The agent is instructed to read and write button configuration files within specific object directories.
- Boundary markers: None specified; the skill relies on standard YAML and JSON structure for data isolation.
- Capability inventory: The defined buttons support API interactions (ajax), client-side logic (custom actions), and event broadcasting within the Steedos framework.
- Sanitization: The skill focus is on configuration templates and does not explicitly implement sanitization of the Amis JSON schema content.
Audit Metadata