review-public-api
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection Surface]: The skill ingests untrusted data in the form of API proposals and code diffs provided by the user (SKILL.md). This represents a surface for indirect prompt injection where malicious instructions could be embedded in the data. However, the skill lacks capabilities for network access, file system modifications, or command execution, which mitigates the risk.
- [Reference Material Usage]: The skill utilizes external technical documentation from trusted sources to inform its reviews. These resources are accessed for informational purposes and do not involve execution of untrusted remote code.
Audit Metadata