NYC

asc-id-resolver

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFE
Full Analysis
  • Prompt Injection (SAFE): No instructions found that attempt to override system behavior or bypass safety filters.
  • Data Exposure & Exfiltration (SAFE): No hardcoded secrets or unauthorized data access patterns identified. Environment variable suggestions (e.g., ASC_APP_ID) are for user configuration and do not contain sensitive data.
  • Remote Code Execution (SAFE): No external dependencies or remote scripts are downloaded or executed.
  • Command Execution (SAFE): The skill uses the asc CLI for its documented purposes.
  • Indirect Prompt Injection (LOW):
  • Ingestion points: Processes user-provided app names and IDs via CLI arguments in SKILL.md.
  • Boundary markers: Examples include double quotes for arguments to prevent basic command injection.
  • Capability inventory: Executes sub-commands of the asc CLI tool.
  • Sanitization: Relies on standard shell quoting as demonstrated in the provided usage examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 07:33 PM