protocolsio-integration

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and analyze external protocol data, which could contain instructions intended to manipulate agent behavior. -- Ingestion points: Data enters the context via API calls to retrieve protocols, publications, and comments, specifically through files like protocols_api.md, discussions.md, and additional_features.md. -- Boundary markers: The instructions lack specific guidance on using delimiters or protective wrappers to isolate external protocol content from the agent's core instructions. -- Capability inventory: The skill possesses significant capabilities including creating, updating, and deleting protocols and files via the API, as well as accessing local filesystem data for uploads as described in SKILL.md and file_manager.md. -- Sanitization: There is no documented requirement for the agent to sanitize, escape, or validate the content retrieved from the external API before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 10:12 PM