skills/kensaurus/skills/design-api/Gen Agent Trust Hub

design-api

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from local network endpoints and database schemas to inform API design. This presents a theoretical surface for indirect injection if these sources were compromised.
  • Ingestion points: Found in SKILL.md referencing http://localhost:8080/api-docs and database schema queries.
  • Boundary markers: None explicit for external content.
  • Capability inventory: SQL execution via Supabase MCP and file searching via Grep.
  • Sanitization: No specific sanitization mentioned for ingested documentation text.
  • [COMMAND_EXECUTION]: The skill utilizes SQL commands to inspect the database environment's structure.
  • Evidence: Templates for querying information_schema.columns and information_schema.table_constraints provided in SKILL.md to assist in design reasoning.
  • [EXTERNAL_DOWNLOADS]: The skill attempts to access local network resources for configuration and documentation.
  • Evidence: References to http://localhost:8080/api-docs and http://localhost:8080/naming-conventions for pre-design checks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:48 AM
Security Audit — agent-trust-hub — design-api