universal-api-glue

Warn

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill encourages the agent to 'Automatically generate the authentication and request logic in Python/TS' and 'Permanently add the new Tool to the assistant's active capability set', which facilitates the execution of code generated from untrusted external sources.
  • [COMMAND_EXECUTION]: The instructions to build integration layers and request logic involve the execution of generated scripts to interface with external software.
  • [PROMPT_INJECTION]: The skill has a significant surface for Indirect Prompt Injection as it processes untrusted API documentation to drive automated code generation.
  • Ingestion points: Scraped API documentation and reverse-engineered logic (SKILL.md).
  • Boundary markers: Absent; there are no delimiters or instructions to ignore embedded commands in the source data.
  • Capability inventory: Python/TypeScript code generation, tool registration, and network operations.
  • Sanitization: Absent; the skill does not prescribe any validation or sanitization of the scraped documentation before it is used in logic generation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 19, 2026, 05:40 AM
Security Audit — agent-trust-hub — universal-api-glue