windsurf-api-development

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external API specifications, which introduces a surface for indirect prompt injection via untrusted data.
  • Ingestion points: Cascade reads openapi.yaml and graphql.schema.graphql to generate code and documentation.
  • Boundary markers: The provided instructions do not specify delimiters or instructions to ignore potential commands embedded in specification descriptions.
  • Capability inventory: The skill is configured with Read, Write, Edit, Bash, and Grep tools to perform its generation and implementation tasks.
  • Sanitization: No explicit sanitization or validation logic is defined for processing the content of imported specifications before code generation.
  • [SAFE]: The skill's external references point to official documentation (swagger.io, windsurf.ai) and the author's own professional domains (intentsolutions.io, jeremylongshore.com). No obfuscation, persistence mechanisms, or unauthorized privilege escalations were found. The requested tool permissions are consistent with the stated purpose of code generation and project management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:49 AM
Security Audit — agent-trust-hub — windsurf-api-development