graphql

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to use external documentation tools (mcp__context7__query-docs) to resolve implementation details. This ingestion of external data constitutes a surface for tool output poisoning.\n
  • Ingestion points: External documentation fetched via mcp__context7__query-docs as described in SKILL.md.\n
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore potential injection attempts within the retrieved documentation.\n
  • Capability inventory: While the skill itself is instructional, the agent typically possesses capabilities like file system modification and command execution that could be targeted.\n
  • Sanitization: There is no evidence of sanitization or validation of the content retrieved from the documentation tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:28 PM
Security Audit — agent-trust-hub — graphql