wazoo
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill follows security best practices by using placeholder credentials (wzp_... and wzw_...) and instructing users to set environment variables rather than hardcoding sensitive tokens.
- [SAFE]: All network operations utilize curl to interact with api.wazoo.dev and data.wazoo.dev, which are legitimate infrastructure endpoints for the author wazootech.
- [INDIRECT_PROMPT_INJECTION]: The skill provides the agent with capabilities to retrieve and import external content from knowledge graphs, creating a surface for indirect injection.
- Ingestion points: Data plane search and export API endpoints identified in SKILL.md.
- Boundary markers: Not explicitly defined in the provided curl examples.
- Capability inventory: Interactions are limited to authenticated API requests via curl; the skill does not include any arbitrary command execution, file system modification, or script evaluation based on retrieved data.
- Sanitization: Data is handled through structured API requests.
Audit Metadata