hormuz-strait

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the Hormuz Strait Monitor API, including headlines, summaries, and news descriptions. Malicious content embedded in these external fields could potentially attempt to influence the agent's behavior.
  • Ingestion points: Data is fetched from https://hormuzstraitmonitor.com/api/dashboard and interpreted by the agent according to SKILL.md.
  • Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" warnings for the external data.
  • Capability inventory: The skill is limited to read-only network requests via curl and data presentation; it lacks dangerous capabilities like file system modification or code execution.
  • Sanitization: No explicit sanitization, filtering, or validation of the API-provided strings is mentioned in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:24 AM
Security Audit — agent-trust-hub — hormuz-strait