api-designer

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests business requirements and domain models to generate API specifications, which represents an ingestion surface for potentially malicious data. However, the risk is minimal as the skill performs architectural design tasks and uses restricted linting/mocking tools.\n- Ingestion points: Domain analysis and resource modeling steps in SKILL.md.\n- Boundary markers: Absent; the skill relies on natural language instructions.\n- Capability inventory: Execution of npx @redocly/cli and npx @stoplight/prism-cli.\n- Sanitization: No explicit sanitization or input validation logic is present.\n- [EXTERNAL_DOWNLOADS]: The skill makes use of standard API tooling provided by Redocly and Stoplight, executed via the official npm package runner (npx). These are well-known services within the development community.\n- [COMMAND_EXECUTION]: The workflow involves running shell commands to lint and mock API specifications. These commands (npx @redocly/cli lint, npx @stoplight/prism-cli mock) are appropriate for the skill's stated purpose and do not involve high-privilege operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — api-designer