api-designer
Warn
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
!commandsyntax to execute shell commands at load time. This allows the system to run arbitrary logic before the agent processes the skill body. - Evidence: Multiple instances in
SKILL.mdsuch as!cat skills/_shared/protocols/ux-protocol.md,!cat .production-grade.yaml, and!cat .forgewright/settings.md. - [DATA_EXFILTRATION]: The skill silently reads local configuration files and workspace settings into the agent's context without user notification or approval.
- Evidence:
!cat .production-grade.yamland!cat .forgewright/settings.mdare executed automatically to set defaults and engagement modes. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by ingesting untrusted data from the codebase to influence its design decisions.
- Ingestion points: Reads
.forgewright/codebase-context.mdat load time and instructs the agent to "READ existing API patterns" from the current workspace. - Boundary markers: None identified. Content from external files is directly concatenated into the instruction stream without delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill has extensive file-writing capabilities, including generating OpenAPI specs in
api/openapi/, error schemas inapi/errors/, and documentation indocs/api/. - Sanitization: There is no mention of validating or sanitizing the content of the ingested files before using them to drive the API design process.
Audit Metadata