api-handbook

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown instructions and architectural guidelines. It does not include any scripts, executable code, or commands that could be run by an agent.
  • [SAFE]: The skill promotes security-positive practices including:
  • Mandatory input validation using Zod before side effects.
  • Enforcing authorization in handlers and warning against trusting client-side flags.
  • Guidelines for secure CORS configurations (explicit origins, no wildcards with credentials).
  • Proper use of security headers (e.g., X-Content-Type-Options: nosniff).
  • Explicit instructions to avoid leaking PII (Personally Identifiable Information) in logs and avoiding stack traces in production responses.
  • [EXTERNAL_DOWNLOADS]: The skill contains links to the author's GitHub repository and an NPM package. These are documented as vendor resources and do not involve runtime downloads or execution within the skill's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 03:02 AM
Security Audit — agent-trust-hub — api-handbook