ai-model-web
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from user requests (e.g., preferred model names or conversational prompts) which are then used to influence management API calls and AI model invocations.\n
- Ingestion points: User-specified model identifiers (used in UpdateAIModel and DescribeAIModels) and the 'messages' array passed to generateText/streamText methods in SKILL.md.\n
- Boundary markers: The instructions do not explicitly mandate the use of delimiters, XML-tag wrapping, or specific 'ignore instructions' warnings when passing user-provided prompts to the underlying AI model.\n
- Capability inventory: The agent is instructed to perform environment configuration (callCloudApi for tcb service actions like UpdateAIModel and CreateAIModel) and network operations through the CloudBase SDK based on instructions derived from user input.\n
- Sanitization: The skill lacks explicit instructions for sanitizing or validating user-provided strings before they are interpolated into the GroupName or Model parameters of the Cloud APIs.
Audit Metadata