skills/tinyopsstudio/automation-integration-preflight-skill/automation-integration-preflight-action/Gen Agent Trust Hub
automation-integration-preflight-action
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and summarizes data received from an external API service, creating a potential surface for indirect prompt injection if the source content is malicious.
- Ingestion points: Data returned from the analyze and acceptance-pack endpoints on x402-preflight.tinyopsstudio.com.
- Boundary markers: Instructions specify distinguishing evidence from recommendations but do not define strict delimiters for the external data.
- Capability inventory: The skill processes text and generates summaries or auditable artifacts based on the external data.
- Sanitization: The instructions do not specify sanitization or validation of the structured JSON response before processing.
- [EXTERNAL_DOWNLOADS]: The skill communicates with the vendor's domain to retrieve API specifications and analysis results.
- Evidence: Fetches configuration from https://x402-preflight.tinyopsstudio.com/openapi.json and sends data to the analyze and acceptance-pack endpoints.
Audit Metadata