api-cms-strapi

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: A thorough security review of all skill files identified no malicious patterns, obfuscation techniques, or unauthorized data operations. All provided patterns align with established security best practices for the Strapi framework.
  • [PROMPT_INJECTION]: No instructions designed to override agent safety protocols or hijack behavior were detected. The 'CRITICAL' instructions are technically oriented, ensuring compatibility with the Strapi v5 API.
  • [DATA_EXFILTRATION]: No unauthorized data harvesting or network exfiltration patterns were found. Network requests in code examples are correctly scoped to user-configured environment variables for the Strapi server.
  • [CREDENTIALS_UNSAFE]: No production secrets or insecure hardcoded credentials were identified. Documentation and examples correctly utilize placeholder values and advocate for the use of environment variables for secret management.
  • [COMMAND_EXECUTION]: The skill documents standard Strapi CLI commands (e.g., npx, npm run) used for project initialization and type generation, which are appropriate and expected for developer tooling.
  • [EXTERNAL_DOWNLOADS]: The skill references configuration schemas from the vendor's official GitHub repository (agents-inc). This is a standard and neutral resource reference.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 01:31 AM