api-design-reviewer

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from OpenAPI/Swagger specifications and incorporates content from these files, such as endpoint summaries and schema descriptions, into reports that the agent then processes. This creates a surface for indirect prompt injection where a malicious specification could attempt to influence agent behavior through the audit report.\n
  • Ingestion points: The scripts api_linter.py, api_scorecard.py, and breaking_change_detector.py all ingest user-provided JSON specification files.\n
  • Boundary markers: The generated text reports do not utilize explicit boundary markers or warnings to distinguish between tool-generated analysis and content extracted from the untrusted specification.\n
  • Capability inventory: The scripts have file read and write capabilities as part of their standard execution flow. They do not perform network operations or direct shell execution.\n
  • Sanitization: The scripts do not perform specific sanitization or escaping of the strings extracted from the API specifications before including them in the output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:27 AM
Security Audit — agent-trust-hub — api-design-reviewer