api-documenter

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted API specifications and code snippets to generate documentation and SDKs, creating an ingestion surface for potential indirect prompt injection.\n
  • Ingestion points: Reads OpenAPI/AsyncAPI specs, GraphQL schemas, and code comments provided by users as described in SKILL.md.\n
  • Boundary markers: Absent. The instructions do not direct the agent to treat data as untrusted or use specific delimiters to isolate user input.\n
  • Capability inventory: Generates multi-language SDKs and interactive documentation based on provided schemas.\n
  • Sanitization: Absent. No explicit validation or sanitization of input content is specified in the prompt instructions.\n- [DYNAMIC_EXECUTION]: The skill generates SDKs and code snippets in multiple languages (Python, JavaScript, Go, etc.) based on user-provided API specifications, which involves the automated generation of code templates at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 01:34 AM
Security Audit — agent-trust-hub — api-documenter