api-cms-strapi
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: A thorough security review of all skill files identified no malicious patterns, obfuscation techniques, or unauthorized data operations. All provided patterns align with established security best practices for the Strapi framework.
- [PROMPT_INJECTION]: No instructions designed to override agent safety protocols or hijack behavior were detected. The 'CRITICAL' instructions are technically oriented, ensuring compatibility with the Strapi v5 API.
- [DATA_EXFILTRATION]: No unauthorized data harvesting or network exfiltration patterns were found. Network requests in code examples are correctly scoped to user-configured environment variables for the Strapi server.
- [CREDENTIALS_UNSAFE]: No production secrets or insecure hardcoded credentials were identified. Documentation and examples correctly utilize placeholder values and advocate for the use of environment variables for secret management.
- [COMMAND_EXECUTION]: The skill documents standard Strapi CLI commands (e.g., npx, npm run) used for project initialization and type generation, which are appropriate and expected for developer tooling.
- [EXTERNAL_DOWNLOADS]: The skill references configuration schemas from the vendor's official GitHub repository (agents-inc). This is a standard and neutral resource reference.
Audit Metadata