ai-model-web

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface where untrusted data could influence agent actions through multi-step chains.
  • Ingestion points: The messages array in the generateText and streamText methods accepts arbitrary text content from users (SKILL.md).
  • Boundary markers: The provided code examples do not include specific delimiters or instructions to ignore embedded commands within the processed messages.
  • Capability inventory: The skill uses the callCloudApi tool to perform administrative actions such as UpdateAIModel and CreateAIModel. These actions can modify environment settings, enable/disable models, or register custom AI endpoints (SKILL.md).
  • Sanitization: There is no evidence of sanitization, validation, or escaping of the user-provided message content before it is processed or used in logic that could trigger these administrative capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:21 AM
Security Audit — agent-trust-hub — ai-model-web