api-spec-analyzer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured instructions for analyzing API specifications for the caremaster-tenant-frontend project. It does not perform any direct network operations, file system modifications, or command executions itself. All generated code follows standard development practices, such as using helper functions for token retrieval instead of hardcoding credentials.
- [INDIRECT_PROMPT_INJECTION]: The skill defines an ingestion surface for external data via specific MCP tools used to fetch OpenAPI specifications. The risk is assessed as safe due to the purely informational nature of the skill's output and the lack of dangerous tool capabilities within the skill context. Ingestion points: OpenAPI specifications and referenced resources retrieved via MCP tools (e.g., mcp__Tenant_Management_Portal_API__read_project_oas_f4bjy4). Boundary markers: None explicitly defined to isolate processed documentation content from the agent's instructions. Capability inventory: The skill itself lacks dangerous capabilities; its function is limited to text and code generation for user review. No file-system, network, or subprocess tools are requested or used. Sanitization: No specific sanitization or filtering of the fetched OpenAPI metadata is mentioned.
Audit Metadata