audit-realworld

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches official API specifications and test suites from the realworld-apps/realworld GitHub repository and interacts with the api.realworld.show hosted service. These are well-known, official resources for the RealWorld benchmark project.
  • [COMMAND_EXECUTION]: The skill instructs the agent to run standard API testing tools such as bru, hurl, and newman. These operations are limited to verifying application conformance and are appropriate for an auditing tool.
  • [PROMPT_INJECTION]: As an auditing tool that reads external codebases, the skill is subject to indirect prompt injection risks. This is a standard risk for auditing tools and is mitigated by the skill's structured audit protocol and reliance on objective test results.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:55 AM
Security Audit — agent-trust-hub — audit-realworld