skills/vapiai/skills/create-squad/Gen Agent Trust Hub

create-squad

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill follows security best practices by using environment variables (e.g., VAPI_API_KEY) for credentials and sensitive resource IDs rather than hardcoding them within the scripts or configuration.
  • [SAFE]: All external communication is directed to the verified vendor API (api.vapi.ai), and the instructions include robust safety protocols like mandatory human confirmation for live API mutations to prevent unauthorized changes.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API endpoints but mitigates risk through explicit boundary markers and verification steps.
  • Ingestion points: Assistant and squad configurations are fetched from the Vapi API as described in the Persistent Squad Procedure in SKILL.md.
  • Boundary markers: The instructions explicitly mandate user authorization for live mutations and require manual verification of fields against official documentation.
  • Capability inventory: The skill has the capability to create and update tools and squads via authenticated network requests to the vendor API.
  • Sanitization: The skill requires resolving assistant names to IDs and validating all request payloads against the official Vapi OpenAPI schema.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:59 AM
Security Audit — agent-trust-hub — create-squad