api-documentation

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes project source code and API definitions to automate the creation and updating of Postman collections. This workflow introduces a surface for indirect prompt injection, where malicious instructions embedded in code comments or documentation strings could attempt to influence the agent's behavior or tool usage during the synchronization process.
  • Ingestion points: The skill reads local source code to extract API contracts, schemas, and endpoint definitions (as described in the 'When to Activate' and 'Step 1' sections of SKILL.md).
  • Boundary markers: The instructions do not specify any boundary markers or instructions for the agent to ignore potentially malicious content within the source code being analyzed.
  • Capability inventory: The skill uses a comprehensive set of Postman MCP tools, including postman_createCollection, postman_patchCollection, postman_createCollectionRequest, and postman_createCollectionResponse, which have the ability to modify external state.
  • Sanitization: There are no explicit instructions for the agent to sanitize or validate the extracted API data before passing it to the Postman toolset.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:56 PM
Security Audit — agent-trust-hub — api-documentation