generating-api-contracts

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious behavior, prompt injections, or obfuscation were detected. The skill's functionality is consistent with its stated purpose of API documentation.
  • [EXTERNAL_DOWNLOADS]: The skill references established industry tools and resources, such as the OpenAPI Specification, Pact, and Spectral. These are well-known services within the API development ecosystem.
  • [PROMPT_INJECTION]: The skill ingests untrusted local source code, representing a standard surface for indirect prompt injection.
  • Ingestion points: Scans route handlers and controllers using Grep and Read tools.
  • Boundary markers: None explicitly defined to separate code data from agent instructions.
  • Capability inventory: Utilizes Write, Edit, and restricted Bash(api:contract-*) tools.
  • Sanitization: No content validation or escaping is specified for the scanned data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 11:31 AM
Security Audit — agent-trust-hub — generating-api-contracts