rate-limit-audit
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill uses
curlto make network requests to external endpoints, such ashttps://staging.example.com/api/chat, for testing rate-limiting behavior. These requests target domains outside the whitelisted set. - [COMMAND_EXECUTION]: The skill executes shell commands, including recursive
grepto scan the application directory for specific keywords andcurlwithin loops to simulate high-traffic burst requests. - [PROMPT_INJECTION]: The skill scans local project files to build an inventory of endpoints, which constitutes an indirect prompt injection surface where external data could influence the agent's context.
- Ingestion points: Scanning the
app/apidirectory usinggrepfor route identification. - Boundary markers: None present; the results of file scans are processed without delimiters or instructions to ignore embedded content.
- Capability inventory: The skill has file-read capabilities (
grep) and network-write capabilities (curl) across the audit workflow. - Sanitization: No sanitization or validation is applied to the data extracted from the filesystem before it is used in the audit report.
Audit Metadata