claude-api

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive development guide for the Anthropic Claude API, providing standard implementation patterns for streaming, tool use, vision, and cost optimization features.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials were detected. The skill correctly instructs users to use environment variables for API keys and includes a checklist item to verify keys are not hardcoded.
  • [PROMPT_INJECTION]: The skill proactively warns developers about prompt injection risks when building applications, advising them to sanitize or structure user input within templates rather than passing raw input directly to the model.
  • [EXTERNAL_DOWNLOADS]: The skill references official Anthropic SDKs (anthropic and @anthropic-ai/sdk) as dependencies. These are standard, well-known packages used for the legitimate purpose of API integration.
  • [DATA_EXFILTRATION]: A specific security warning is provided against logging full request/response payloads to prevent the accidental exposure of sensitive user data, demonstrating a defensive security posture.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 10:12 AM
Security Audit — agent-trust-hub — claude-api