api-contract

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to reconcile backend and frontend design documents into a single API contract. All operations are confined to the local workspace and project-specific directories (e.g., .maestro/).
  • [DATA_EXFILTRATION]: No evidence of data exfiltration was found. The skill does not use network-capable tools like curl or wget, and it does not access sensitive system paths or credentials.
  • [COMMAND_EXECUTION]: Although the skill is granted access to the Bash tool, its instructions are strictly scoped to reading and writing project artifacts. There is no usage of dangerous shell patterns or privilege escalation attempts.
  • [PROMPT_INJECTION]: The skill does not contain instructions that attempt to override system prompts, bypass safety guidelines, or extract sensitive information via the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 09:27 AM
Security Audit — agent-trust-hub — api-contract