http-api-cloudbase
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest external data from a knowledge base to generate code and commands, creating a potential injection surface.
- Ingestion points: Instructions in
SKILL.mdandreferences/extended-guide.mddirect the agent to use thesearchKnowledgeBasetool to fetch OpenAPI specifications. - Boundary markers: The instructions do not provide delimiters or "ignore embedded instructions" warnings to the agent for when it processes the fetched YAML content.
- Capability inventory: The agent uses the fetched data to construct and potentially execute shell commands (
curl) and HTTP requests. - Sanitization: There are no requirements or steps provided for the agent to validate, escape, or sanitize the content returned by the knowledge base tool before using it to generate implementation code.
Audit Metadata