api-patterns
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill primarily consists of architectural guidance and best practices for API development. No prompt injection or malicious instructions were found in the markdown files.
- [COMMAND_EXECUTION]: The skill includes a script
scripts/api_validator.pywhich is designed to be executed locally. This script performs static analysis on project files (e.g., checking for the presence of error handling, status codes, and input validation) using regex and JSON parsing. It does not execute the target code it analyzes. - [DATA_EXFILTRATION]: The validation script operates exclusively on the local filesystem using the
pathlibmodule. It contains no network-related code (no use ofrequests,urllib, or socket libraries) and does not send any data to external servers. - [INDIRECT_PROMPT_INJECTION]: The
api_validator.pyscript represents a minor indirect prompt injection surface as it reads and reports on the contents of user-provided project files. However, the script is limited to scanning 15 files and performs purely diagnostic tasks, making the risk negligible. - [EXTERNAL_DOWNLOADS]: No external dependencies are required; the provided script uses only Python's standard library.
Audit Metadata