http-api-cloudbase

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and processing of data from external CloudBase API endpoints (databases, functions, storage), creating a potential surface for indirect prompt injection if the remote data contains adversarial instructions.
  • Ingestion points: API response bodies from database queries, function invocations, and AI model responses as described in SKILL.md and references/extended-guide.md.
  • Boundary markers: The skill does not explicitly define delimiters for parsing incoming API response data, relying on standard JSON/EJSON structures.
  • Capability inventory: The agent is instructed to use network clients (e.g., curl) and authentication headers to retrieve and manipulate remote resources.
  • Sanitization: The guide provides instructions for URL encoding outgoing parameters to ensure correct request formatting, though it lacks specific validation steps for incoming response content beyond standard error handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:21 AM
Security Audit — agent-trust-hub — http-api-cloudbase