api-designer
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill's workflow includes instructions to use
npx @redocly/clifor linting OpenAPI specifications andnpx @stoplight/prism-clifor running mock servers. These are industry-standard tools for API development and are consistent with the skill's primary purpose. - [EXTERNAL_DOWNLOADS]: The use of
npximplicitly involves fetching packages from the official npm registry. As this targets a well-known service for standard development tasks, it is considered a safe and expected operation. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process domain requirements and business logic provided by users to generate API specifications.
- Ingestion points: Business requirements and data models provided during the 'Analyze domain' phase.
- Boundary markers: The instructions do not explicitly define delimiters for user-provided content.
- Capability inventory: The agent has the capability to write YAML files (
openapi.yaml) and execute shell commands (npx). - Sanitization: No explicit sanitization or instruction-ignoring prompts are present for the processed domain data. However, the risk is inherent to the specialized architectural task and does not indicate malicious intent.
Audit Metadata