api-documentation
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes project source code and API definitions to automate the creation and updating of Postman collections. This workflow introduces a surface for indirect prompt injection, where malicious instructions embedded in code comments or documentation strings could attempt to influence the agent's behavior or tool usage during the synchronization process.
- Ingestion points: The skill reads local source code to extract API contracts, schemas, and endpoint definitions (as described in the 'When to Activate' and 'Step 1' sections of SKILL.md).
- Boundary markers: The instructions do not specify any boundary markers or instructions for the agent to ignore potentially malicious content within the source code being analyzed.
- Capability inventory: The skill uses a comprehensive set of Postman MCP tools, including
postman_createCollection,postman_patchCollection,postman_createCollectionRequest, andpostman_createCollectionResponse, which have the ability to modify external state. - Sanitization: There are no explicit instructions for the agent to sanitize or validate the extracted API data before passing it to the Postman toolset.
Audit Metadata