spring-boot-rest-api-standards
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a documentation-focused resource providing Spring Boot development standards and boilerplate templates.
- [SAFE]: It contains extensive security guidance, including implementation of security headers (CSP, HSTS, X-Frame-Options), JWT authentication filters, and input validation to prevent path traversal in file uploads.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to analyze and design APIs based on user-provided code and requirements.
- Ingestion points: The agent reads code from the local filesystem using tools like Read, Glob, and Grep when performing analysis tasks.
- Boundary markers: The instructions do not define specific delimiters to separate user-provided code from instructions.
- Capability inventory: The skill has access to tools capable of system modification, including Write, Edit, and Bash.
- Sanitization: No content-level validation is specified for user-provided data within the skill's instructions.
Audit Metadata