agent-api-designer

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The installation command fetches the skill definition from a public GitHub repository (raw.githubusercontent.com/majiayu000/claude-skill-registry). GitHub is a well-known service for hosting code and configurations.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and design APIs based on user-provided requirements. It utilizes powerful tools such as Bash and Write, but lacks explicit boundary markers or instructions to sanitize or ignore embedded commands within the ingested technical specifications.\n
  • Ingestion points: User-provided API requirements and technical descriptions (SKILL.md).\n
  • Boundary markers: None identified.\n
  • Capability inventory: Bash, Write, MultiEdit, openapi-generator, graphql-codegen (SKILL.md).\n
  • Sanitization: None identified.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 06:27 AM
Security Audit — agent-trust-hub — agent-api-designer