api-patterns

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill primarily consists of architectural guidance and best practices for API development. No prompt injection or malicious instructions were found in the markdown files.
  • [COMMAND_EXECUTION]: The skill includes a script scripts/api_validator.py which is designed to be executed locally. This script performs static analysis on project files (e.g., checking for the presence of error handling, status codes, and input validation) using regex and JSON parsing. It does not execute the target code it analyzes.
  • [DATA_EXFILTRATION]: The validation script operates exclusively on the local filesystem using the pathlib module. It contains no network-related code (no use of requests, urllib, or socket libraries) and does not send any data to external servers.
  • [INDIRECT_PROMPT_INJECTION]: The api_validator.py script represents a minor indirect prompt injection surface as it reads and reports on the contents of user-provided project files. However, the script is limited to scanning 15 files and performs purely diagnostic tasks, making the risk negligible.
  • [EXTERNAL_DOWNLOADS]: No external dependencies are required; the provided script uses only Python's standard library.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 07:45 AM
Security Audit — agent-trust-hub — api-patterns