claude-api

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a pattern for processing untrusted user input within an LLM context.
    • Ingestion points: User messages passed via the messages array in code examples.
    • Boundary markers: None explicitly shown in the basic prompt construction examples.
    • Capability inventory: Server-side tool execution logic described in the 'Tool use' section.
    • Sanitization: The documentation recommends JSON schema validation for tool arguments and human confirmation for destructive actions.
  • [EXTERNAL_DOWNLOADS]: The skill references official SDKs and API endpoints for Anthropic, including the well-known api.anthropic.com endpoint, the @anthropic-ai/sdk for Node.js, and the anthropic Python package.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 05:51 PM
Security Audit — agent-trust-hub — claude-api