api-designer
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill workflow involves executing standard industry tools via the Node Package Runner (npx).
- Evidence:
npx @redocly/cli lint openapi.yamlandnpx @stoplight/prism-cli mock openapi.yamlare specified inSKILL.mdfor validating and testing API contracts. - Context: These tools are well-known in the API development community and are used here for their intended technical purposes.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external business requirements and domain models to generate API specifications, representing a typical ingestion surface.
- Ingestion points: Ingests "business requirements, data models, and client needs" as part of the core workflow in
SKILL.md. - Boundary markers: The skill relies on structured output (YAML/JSON) which inherently provides some level of output separation, though explicit instruction delimiters for user input are not defined.
- Capability inventory: The skill has the capability to run CLI tools (
npx,openapi-generator-cli) and generate code stubs. - Sanitization: No specific sanitization logic is provided, however, the risk is minimized by the technical nature of the output (contract specifications).
- [SAFE]: The instructions and reference documents provide high-quality, best-practice-oriented guidance. No evidence of obfuscation, privilege escalation, data exfiltration, or hardcoded credentials was found.
Audit Metadata