generating-api-contracts
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior, prompt injections, or obfuscation were detected. The skill's functionality is consistent with its stated purpose of API documentation.
- [EXTERNAL_DOWNLOADS]: The skill references established industry tools and resources, such as the OpenAPI Specification, Pact, and Spectral. These are well-known services within the API development ecosystem.
- [PROMPT_INJECTION]: The skill ingests untrusted local source code, representing a standard surface for indirect prompt injection.
- Ingestion points: Scans route handlers and controllers using Grep and Read tools.
- Boundary markers: None explicitly defined to separate code data from agent instructions.
- Capability inventory: Utilizes Write, Edit, and restricted Bash(api:contract-*) tools.
- Sanitization: No content validation or escaping is specified for the scanned data.
Audit Metadata