swagger-doc-creator
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and metadata were analyzed for all 11 threat categories including prompt injection, data exfiltration, and obfuscation. No malicious patterns were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external API specifications and source code, creating a potential surface for indirect prompt injection. This is inherent to its primary purpose of documentation generation. Evidence chain: 1. Ingestion points: User-provided API specifications and source code; 2. Boundary markers: Absent; 3. Capability inventory: Read, Write, Edit, Bash(curl:*), and Grep (SKILL.md); 4. Sanitization: Instructions mention validating outputs against common industry standards.
Audit Metadata