api-designer
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests business requirements and domain models to generate API specifications, which represents an ingestion surface for potentially malicious data. However, the risk is minimal as the skill performs architectural design tasks and uses restricted linting/mocking tools.\n- Ingestion points: Domain analysis and resource modeling steps in
SKILL.md.\n- Boundary markers: Absent; the skill relies on natural language instructions.\n- Capability inventory: Execution ofnpx @redocly/cliandnpx @stoplight/prism-cli.\n- Sanitization: No explicit sanitization or input validation logic is present.\n- [EXTERNAL_DOWNLOADS]: The skill makes use of standard API tooling provided by Redocly and Stoplight, executed via the official npm package runner (npx). These are well-known services within the development community.\n- [COMMAND_EXECUTION]: The workflow involves running shell commands to lint and mock API specifications. These commands (npx @redocly/cli lint,npx @stoplight/prism-cli mock) are appropriate for the skill's stated purpose and do not involve high-privilege operations.
Audit Metadata