api-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a Python validation script (scripts/api_validator.py) designed to scan local project directories for API implementation best practices. The script uses standard libraries and performs read-only filesystem operations.
  • [INDIRECT_PROMPT_INJECTION]: The api_validator.py script ingests data from external project files to perform its analysis. The output of this script is then processed by the agent, creating a potential surface for indirect prompt injection if the scanned files contain malicious instructions.
  • Ingestion points: scripts/api_validator.py reads content from files in a user-specified project path.
  • Boundary markers: The script output does not include specific delimiters to isolate potentially untrusted file content or names from the agent's instructions.
  • Capability inventory: The skill utilizes Read, Write, Edit, Glob, and Grep tools.
  • Sanitization: The script uses regular expressions to identify patterns and does not directly output raw file content, though it does report findings based on that content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — api-patterns