api-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a Python validation script (
scripts/api_validator.py) designed to scan local project directories for API implementation best practices. The script uses standard libraries and performs read-only filesystem operations. - [INDIRECT_PROMPT_INJECTION]: The
api_validator.pyscript ingests data from external project files to perform its analysis. The output of this script is then processed by the agent, creating a potential surface for indirect prompt injection if the scanned files contain malicious instructions. - Ingestion points:
scripts/api_validator.pyreads content from files in a user-specified project path. - Boundary markers: The script output does not include specific delimiters to isolate potentially untrusted file content or names from the agent's instructions.
- Capability inventory: The skill utilizes
Read,Write,Edit,Glob, andGreptools. - Sanitization: The script uses regular expressions to identify patterns and does not directly output raw file content, though it does report findings based on that content.
Audit Metadata