audit-api

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The instruction 'If clear, add/remove without consulting the user' bypasses the standard human-in-the-loop safety protocol for potentially destructive code modifications.
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection as it processes API definitions and functionality descriptions to determine changes. Ingestion points: Codebase API definitions and documentation. Boundary markers: Not used to isolate external data from instructions. Capability inventory: Modification of project files and code generation. Sanitization: No sanitization or validation of the ingested data is performed.
  • [NO_CODE]: The skill consists entirely of natural language instructions within the SKILL.md file and does not include any external scripts or executables.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 10:21 AM
Security Audit — agent-trust-hub — audit-api