version-api

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The EXAMPLES.md file provides a code snippet for header-based versioning that uses .constantize on a string derived from the Accept request header. This pattern constitutes unsafe reflection and is explicitly forbidden by the skill's own safety guidelines in SKILL.md. It risks exposing internal application constants to external triggers.\n- [PROMPT_INJECTION]: The skill exhibits a safety bypass pattern where the reference implementation in EXAMPLES.md contradicts the 'HARD-GATE' security constraints defined in SKILL.md. By providing a 'forbidden' implementation as a helpful example, the skill may trick the AI agent into generating insecure code that bypasses its intended security filters.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 05:23 PM
Security Audit — agent-trust-hub — version-api