olakai-integrate

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is designed to capture and transmit LLM interaction data, including prompts, responses, and custom metadata, to the Olakai platform (app.olakai.ai). This data transfer is the core functionality required for providing monitoring and analytics services.
  • [EXTERNAL_DOWNLOADS]: The instructions direct users to install the Olakai CLI and SDKs (@olakai/sdk and olakai-sdk) via standard package managers. These are verified as vendor-owned resources associated with the skill author, olakai-ai.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by handling untrusted data. 1. Ingestion points: The prompt and response data from LLM calls are captured by the SDK in SKILL.md. 2. Boundary markers: No specific delimiters or 'ignore' instructions for embedded content are mentioned in the integration guide. 3. Capability inventory: The skill has the capability to send captured data via network requests to a remote service. 4. Sanitization: No explicit sanitization or filtering of LLM outputs is documented before the data is processed and sent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 06:56 AM