giime-components
Pass
Audited by Gen Agent Trust Hub on Mar 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to configure a Model Context Protocol (MCP) server using the URL
https://genapi-giime.giikin.com/mcp. This endpoint is hosted on the vendor's domain and is used to fetch component documentation. - [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by design, as the agent is instructed to fetch and follow guidance from external documentation via the
get-giime-component-doctool. - Ingestion points: Documentation content retrieved from
genapi-giime.giikin.comvia MCP tools (SKILL.md). - Boundary markers: None specified in the instructions for handling the external data.
- Capability inventory: Code generation and modification based on documentation.
- Sanitization: No explicit sanitization or validation of the retrieved documentation content is mentioned.
Audit Metadata