thirds-batch-files

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data provided by the user (CSV or JSON rows). It mitigates potential injection risks by instructing the agent to parse data into structured JSON and requiring a user review of the mapped fields and row count before execution.
  • [CREDENTIALS_UNSAFE]: The instructions acknowledge the use of private API keys for connection. It explicitly commands the agent to keep these credentials private, aligning with secure secret handling practices.
  • [COMMAND_EXECUTION]: The skill uses specific batch management tools (e.g., create_batch, list_templates, get_status). These are restricted to the vendor's API functionality for rendering templates and do not involve arbitrary system command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 02:08 PM
Security Audit — agent-trust-hub — thirds-batch-files