rest-api-design
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for implementing API handlers that process external data, which is an inherent attack surface.\n
- Ingestion points: The skill provides templates in
SKILL.mdthat ingest untrusted data viarequest.json()in Next.js route handlers.\n - Boundary markers: The skill advocates for the use of Zod schemas to validate all incoming data (
RequestSchema.safeParse(body)), which establishes a strong security boundary to mitigate injection attacks.\n - Capability inventory: The skill environment has
Write,Edit, andBash(restricted to npm and npx) capabilities enabled.\n - Sanitization: Strict type checking and validation are enforced through Zod patterns (e.g.,
email,uuid,datetime, and numeric constraints) to ensure data integrity before processing.
Audit Metadata