api-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No security issues were identified in the skill instructions or scripts. The validation script performs local analysis on user-provided paths without network connectivity or privileged actions. The content is purely educational and provides best practices for API design and testing.- [INDIRECT_PROMPT_INJECTION]: The validation script (
scripts/api_validator.py) ingests and processes content from project files, creating an ingestion surface for potential indirect prompt injection from untrusted data. - Ingestion points: The script uses
Path.globto locate files andPath.read_textto ingest content inscripts/api_validator.py. - Boundary markers: No explicit boundary markers or delimiters are defined for the agent when processing the script's output.
- Capability inventory: The script performs read-only static analysis and prints findings to the console. The agent's allowed tools are limited to
Read,Write,Edit,Glob, andGrepper the skill frontmatter. - Sanitization: Data is analyzed using standard
json.loadsandre.searchpatterns, providing basic structure-based filtering. The risk is considered minimal due to the analytical nature of the tool.
Audit Metadata