api-realtime
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation includes commands for installing well-known libraries and tools via package managers such as npm and pip. It also references an official installation script for the Apollo Rover CLI from a recognized industry domain (rover.apollo.dev).
- [PROMPT_INJECTION]: As a routing agent for API technology, the skill processes user-provided queries and specification text, creating a surface for indirect prompt injection. 1. Ingestion points: User-provided architectural questions and API specification snippets processed via SKILL.md. 2. Boundary markers: The skill does not employ specific delimiters to isolate user-provided data. 3. Capability inventory: The skill does not define any external tools or executable scripts, and the provided code is strictly for documentation. 4. Sanitization: No sanitization logic is present for user-provided specification content.
- [SAFE]: Thorough analysis of the 45 files confirms that the skill serves as a legitimate educational and routing resource. No hidden code, unauthorized persistence mechanisms, or credential harvesting patterns were found.
Audit Metadata