develop-ai-functions-example
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- Indirect Prompt Injection (LOW): The skill provides templates for AI functions and tools that process untrusted natural language input, creating a potential surface for indirect prompt injection.
- Ingestion points: The
promptparameter ingenerateText,streamText, andgenerateObjecttemplates, as well as theinputSchemafor custom tools. - Boundary markers: None are specified or implemented in the provided templates to delimit untrusted input.
- Capability inventory: The skill environment supports network operations (AI provider API calls), file system writes (
save-audio.ts), and local command execution (pnpm tsx). - Sanitization: No explicit sanitization or validation logic is included in the templates for interpolated prompts.
- Data Exposure (SAFE): The skill mentions a
run.tsutility that loads environment variables from a.envfile. This is a standard practice for local development and no exfiltration patterns or hardcoded credentials were found. - Command Execution (SAFE): The documentation includes commands to run scripts via
pnpm tsx. These are standard developer operations and do not represent unauthorized privilege escalation or malicious persistence.
Audit Metadata