api-realtime

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes commands for installing well-known libraries and tools via package managers such as npm and pip. It also references an official installation script for the Apollo Rover CLI from a recognized industry domain (rover.apollo.dev).
  • [PROMPT_INJECTION]: As a routing agent for API technology, the skill processes user-provided queries and specification text, creating a surface for indirect prompt injection. 1. Ingestion points: User-provided architectural questions and API specification snippets processed via SKILL.md. 2. Boundary markers: The skill does not employ specific delimiters to isolate user-provided data. 3. Capability inventory: The skill does not define any external tools or executable scripts, and the provided code is strictly for documentation. 4. Sanitization: No sanitization logic is present for user-provided specification content.
  • [SAFE]: Thorough analysis of the 45 files confirms that the skill serves as a legitimate educational and routing resource. No hidden code, unauthorized persistence mechanisms, or credential harvesting patterns were found.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 11:19 PM
Security Audit — agent-trust-hub — api-realtime