api-designer

Warn

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the !command syntax to execute shell commands at load time. This allows the system to run arbitrary logic before the agent processes the skill body.
  • Evidence: Multiple instances in SKILL.md such as !cat skills/_shared/protocols/ux-protocol.md, !cat .production-grade.yaml, and !cat .forgewright/settings.md.
  • [DATA_EXFILTRATION]: The skill silently reads local configuration files and workspace settings into the agent's context without user notification or approval.
  • Evidence: !cat .production-grade.yaml and !cat .forgewright/settings.md are executed automatically to set defaults and engagement modes.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by ingesting untrusted data from the codebase to influence its design decisions.
  • Ingestion points: Reads .forgewright/codebase-context.md at load time and instructs the agent to "READ existing API patterns" from the current workspace.
  • Boundary markers: None identified. Content from external files is directly concatenated into the instruction stream without delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill has extensive file-writing capabilities, including generating OpenAPI specs in api/openapi/, error schemas in api/errors/, and documentation in docs/api/.
  • Sanitization: There is no mention of validating or sanitizing the content of the ingested files before using them to drive the API design process.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 1, 2026, 07:55 AM
Security Audit — agent-trust-hub — api-designer