rest-api-design

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for implementing API handlers that process external data, which is an inherent attack surface.\n
  • Ingestion points: The skill provides templates in SKILL.md that ingest untrusted data via request.json() in Next.js route handlers.\n
  • Boundary markers: The skill advocates for the use of Zod schemas to validate all incoming data (RequestSchema.safeParse(body)), which establishes a strong security boundary to mitigate injection attacks.\n
  • Capability inventory: The skill environment has Write, Edit, and Bash (restricted to npm and npx) capabilities enabled.\n
  • Sanitization: Strict type checking and validation are enforced through Zod patterns (e.g., email, uuid, datetime, and numeric constraints) to ensure data integrity before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:35 PM
Security Audit — agent-trust-hub — rest-api-design