create-tool
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external API responses, which presents a surface for instructions embedded in data. 1. Ingestion points: Configuration data fetched via GET /tool and GET /assistant (SKILL.md). 2. Boundary markers: Absent; the skill lacks specific instructions to ignore text instructions within API data. 3. Capability inventory: Network operations and assistant model modification (SKILL.md, references/api-examples.md). 4. Sanitization: Absent.
- [EXTERNAL_DOWNLOADS]: The skill references an official vendor package. Evidence: Documentation recommends @vapi-ai/server-sdk (references/api-examples.md).
- [COMMAND_EXECUTION]: The skill includes command-line tool templates. Evidence: Provides cURL command examples for interacting with the API (references/api-examples.md).
Audit Metadata