passkit

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as coupon codes and Wallet pass bundles, which creates an attack surface for indirect prompt injection if the data contains malicious instructions targeting the agent. * Ingestion points: Data enters through PKPass(data:) in both the main skill and reference files, and the couponCode parameter in delegate methods. * Boundary markers: No explicit delimiters are used to separate external data from agent instructions. * Capability inventory: The skill utilizes PKPassLibrary for managing passes and makes network requests via a paymentService to process tokens. * Sanitization: PKPass validates signatures, but no text-level sanitization is present for coupon codes or pass metadata.
  • [EXTERNAL_DOWNLOADS]: Documentation links point to the sosumi.ai domain. While used as placeholders for official documentation, this is a non-whitelisted external source.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 11:13 AM
Security Audit — agent-trust-hub — passkit