api-documenter
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted API specifications and code snippets to generate documentation and SDKs, creating an ingestion surface for potential indirect prompt injection.\n
- Ingestion points: Reads OpenAPI/AsyncAPI specs, GraphQL schemas, and code comments provided by users as described in
SKILL.md.\n - Boundary markers: Absent. The instructions do not direct the agent to treat data as untrusted or use specific delimiters to isolate user input.\n
- Capability inventory: Generates multi-language SDKs and interactive documentation based on provided schemas.\n
- Sanitization: Absent. No explicit validation or sanitization of input content is specified in the prompt instructions.\n- [DYNAMIC_EXECUTION]: The skill generates SDKs and code snippets in multiple languages (Python, JavaScript, Go, etc.) based on user-provided API specifications, which involves the automated generation of code templates at runtime.
Audit Metadata