api-design

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional content and does not include any executable code, scripts, or package dependencies.
  • [EXTERNAL_DOWNLOADS]: The skill references a JSON evaluation artifact hosted on the author's GitHub repository (jacob-balslev/skill-graph). This reference is informative and does not involve automated execution.
  • [SAFE]: The allowed-tools configuration is restricted to Read and Grep, which limits the agent to read-only file system operations and prevents invasive actions.
  • [PROMPT_INJECTION]: The skill performs reviews of user-provided API contracts, which constitutes an ingestion surface for untrusted data. However, given the limited tool set and the nature of the task, the risk of indirect prompt injection is minimal.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 10:49 AM