api-architect

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides architecture templates and validation scripts for API design. The bash script scripts/validate-api-spec.sh performs static analysis (grep-based) on local specification files to ensure they follow best practices (e.g., using nouns in URLs, defining security schemes). It does not execute remote code or exfiltrate data.
  • [SAFE]: The allowed-tools section correctly restricts Bash usage to specific package managers (npm, npx) and the openapi-generator, which are standard tools for API development.
  • [SAFE]: Reference files in ./references/ contain standard configurations for authentication (OAuth2, JWT) and rate limiting. The placeholders used (e.g., https://auth.example.com) are standard for documentation and do not expose real credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:09 PM
Security Audit — agent-trust-hub — api-architect