api-contract
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to reconcile backend and frontend design documents into a single API contract. All operations are confined to the local workspace and project-specific directories (e.g.,
.maestro/). - [DATA_EXFILTRATION]: No evidence of data exfiltration was found. The skill does not use network-capable tools like
curlorwget, and it does not access sensitive system paths or credentials. - [COMMAND_EXECUTION]: Although the skill is granted access to the
Bashtool, its instructions are strictly scoped to reading and writing project artifacts. There is no usage of dangerous shell patterns or privilege escalation attempts. - [PROMPT_INJECTION]: The skill does not contain instructions that attempt to override system prompts, bypass safety guidelines, or extract sensitive information via the LLM.
Audit Metadata