api-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No security issues were identified in the skill instructions or scripts. The validation script performs local analysis on user-provided paths without network connectivity or privileged actions. The content is purely educational and provides best practices for API design and testing.- [INDIRECT_PROMPT_INJECTION]: The validation script (scripts/api_validator.py) ingests and processes content from project files, creating an ingestion surface for potential indirect prompt injection from untrusted data.
  • Ingestion points: The script uses Path.glob to locate files and Path.read_text to ingest content in scripts/api_validator.py.
  • Boundary markers: No explicit boundary markers or delimiters are defined for the agent when processing the script's output.
  • Capability inventory: The script performs read-only static analysis and prints findings to the console. The agent's allowed tools are limited to Read, Write, Edit, Glob, and Grep per the skill frontmatter.
  • Sanitization: Data is analyzed using standard json.loads and re.search patterns, providing basic structure-based filtering. The risk is considered minimal due to the analytical nature of the tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — api-patterns