http-api-cloudbase
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion and processing of data from external CloudBase API endpoints (databases, functions, storage), creating a potential surface for indirect prompt injection if the remote data contains adversarial instructions.
- Ingestion points: API response bodies from database queries, function invocations, and AI model responses as described in
SKILL.mdandreferences/extended-guide.md. - Boundary markers: The skill does not explicitly define delimiters for parsing incoming API response data, relying on standard JSON/EJSON structures.
- Capability inventory: The agent is instructed to use network clients (e.g.,
curl) and authentication headers to retrieve and manipulate remote resources. - Sanitization: The guide provides instructions for URL encoding outgoing parameters to ensure correct request formatting, though it lacks specific validation steps for incoming response content beyond standard error handling.
Audit Metadata