thirds-batch-files
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data provided by the user (CSV or JSON rows). It mitigates potential injection risks by instructing the agent to parse data into structured JSON and requiring a user review of the mapped fields and row count before execution.
- [CREDENTIALS_UNSAFE]: The instructions acknowledge the use of private API keys for connection. It explicitly commands the agent to keep these credentials private, aligning with secure secret handling practices.
- [COMMAND_EXECUTION]: The skill uses specific batch management tools (e.g.,
create_batch,list_templates,get_status). These are restricted to the vendor's API functionality for rendering templates and do not involve arbitrary system command execution.
Audit Metadata