object-buttons

Pass

Audited by Gen Agent Trust Hub on Apr 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines legitimate configuration patterns for the Steedos platform. The examples provided for AJAX calls, navigation, and logic are consistent with official platform documentation.
  • [PROMPT_INJECTION]: The skill describes a surface for indirect prompt injection through the processing of .button.yml configuration files.
  • Ingestion points: The agent is instructed to read and write button configuration files within specific object directories.
  • Boundary markers: None specified; the skill relies on standard YAML and JSON structure for data isolation.
  • Capability inventory: The defined buttons support API interactions (ajax), client-side logic (custom actions), and event broadcasting within the Steedos framework.
  • Sanitization: The skill focus is on configuration templates and does not explicitly implement sanitization of the Amis JSON schema content.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 23, 2026, 03:02 AM
Security Audit — agent-trust-hub — object-buttons