auditing-api-contracts
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security vulnerabilities were detected. The skill's behavior is consistent with its stated purpose of reverse-engineering and documenting API structures from a legacy codebase.\n- [DATA_EXFILTRATION]: The skill reads local application source code files (e.g.,
routes/,controllers/) within the project structure. This access is limited to application logic and does not involve accessing sensitive system credentials or performing network exfiltration.\n- [PROMPT_INJECTION]: The skill processes external source code as input. Since the agent's capabilities are restricted to generating documentation artifacts, there is no risk of instruction execution from malicious code comments.
Audit Metadata