api-test-suite-builder
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides pre-defined shell commands using standard utilities like
find,grep, andsedto scan project directories and extract route definitions from source files across various frameworks (Node.js, Python, Go). - [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and analyzing untrusted source code and OpenAPI specifications, creating a potential surface for instructions embedded in data to influence the agent.
- Ingestion points: The agent reads route handler source files and parses OpenAPI JSON specifications from the user's workspace.
- Boundary markers: The instructions do not specify any delimiters or safety markers to isolate the content of the analyzed files from the agent's command context.
- Capability inventory: The agent has the capability to execute local Python scripts, perform shell command operations, and write new test files based on the analysis of external content.
- Sanitization: While the provided scripts validate schemas and patterns, there is no explicit sanitization for natural language instructions within the processed data.
- [EXTERNAL_DOWNLOADS]: The skill and its scripts reference and facilitate the use of established third-party testing frameworks and libraries, including Vitest, Supertest, Pact, and k6.
Audit Metadata