api-test-suite-builder

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides pre-defined shell commands using standard utilities like find, grep, and sed to scan project directories and extract route definitions from source files across various frameworks (Node.js, Python, Go).
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and analyzing untrusted source code and OpenAPI specifications, creating a potential surface for instructions embedded in data to influence the agent.
  • Ingestion points: The agent reads route handler source files and parses OpenAPI JSON specifications from the user's workspace.
  • Boundary markers: The instructions do not specify any delimiters or safety markers to isolate the content of the analyzed files from the agent's command context.
  • Capability inventory: The agent has the capability to execute local Python scripts, perform shell command operations, and write new test files based on the analysis of external content.
  • Sanitization: While the provided scripts validate schemas and patterns, there is no explicit sanitization for natural language instructions within the processed data.
  • [EXTERNAL_DOWNLOADS]: The skill and its scripts reference and facilitate the use of established third-party testing frameworks and libraries, including Vitest, Supertest, Pact, and k6.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:46 AM
Security Audit — agent-trust-hub — api-test-suite-builder