plan-tour-route
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches geocoding information and point-of-interest details from OpenStreetMap services (Nominatim and Overpass APIs).- [COMMAND_EXECUTION]: Uses the Bash tool to perform mathematical calculations for distance estimation and to run route optimization heuristics.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. Ingestion points: Waypoint labels from user input and location descriptions retrieved from external mapping APIs. Boundary markers: None identified; the skill does not use delimiters to isolate untrusted geographic data. Capability inventory: Accesses Bash, Write, and Edit tools which could be leveraged if malicious instructions are processed. Sanitization: No validation or escaping is applied to the retrieved location strings before they are incorporated into the workflow.
Audit Metadata