ai-model-web
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface where untrusted data could influence agent actions through multi-step chains.
- Ingestion points: The
messagesarray in thegenerateTextandstreamTextmethods accepts arbitrary text content from users (SKILL.md). - Boundary markers: The provided code examples do not include specific delimiters or instructions to ignore embedded commands within the processed messages.
- Capability inventory: The skill uses the
callCloudApitool to perform administrative actions such asUpdateAIModelandCreateAIModel. These actions can modify environment settings, enable/disable models, or register custom AI endpoints (SKILL.md). - Sanitization: There is no evidence of sanitization, validation, or escaping of the user-provided message content before it is processed or used in logic that could trigger these administrative capabilities.
Audit Metadata