apiiro-secure-prompt

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the apiiro CLI tool (apiiro guardian secure-prompt) to process coding tasks provided by the user. This is the primary function of the skill and utilizes the vendor's own tooling to provide security enhancements.
  • [DATA_EXPOSURE]: The tool is designed to auto-detect and read context from the current git repository. While this involves local file system access, it is a documented and expected behavior for a repository-aware security utility aiming to provide targeted guidance.
  • [PROMPT_INJECTION]: The skill takes user-provided task descriptions and processes them. While this represents a surface for indirect prompt injection, the tool's specific purpose is to wrap and enhance the input with security guardrails, which aligns with safe operational practices for this use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 05:35 PM