api-designer

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill's workflow includes instructions to use npx @redocly/cli for linting OpenAPI specifications and npx @stoplight/prism-cli for running mock servers. These are industry-standard tools for API development and are consistent with the skill's primary purpose.
  • [EXTERNAL_DOWNLOADS]: The use of npx implicitly involves fetching packages from the official npm registry. As this targets a well-known service for standard development tasks, it is considered a safe and expected operation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process domain requirements and business logic provided by users to generate API specifications.
  • Ingestion points: Business requirements and data models provided during the 'Analyze domain' phase.
  • Boundary markers: The instructions do not explicitly define delimiters for user-provided content.
  • Capability inventory: The agent has the capability to write YAML files (openapi.yaml) and execute shell commands (npx).
  • Sanitization: No explicit sanitization or instruction-ignoring prompts are present for the processed domain data. However, the risk is inherent to the specialized architectural task and does not indicate malicious intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:29 PM
Security Audit — agent-trust-hub — api-designer