klh-openapi-directory-first

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Analysis of the automated alerts indicates they are false positives. The skill uses curl to pipe JSON data into a hardcoded Python script (python3 -c) for parsing; it does not execute code downloaded from the network.
  • [EXTERNAL_DOWNLOADS]: Fetches public API specifications from GitHub and APIs.guru. These are well-known, reputable sources for machine-readable API documentation required for the skill's functionality.
  • [COMMAND_EXECUTION]: Uses curl and python3 locally to search directory listings and fetch specifications. This is a standard approach for interacting with the GitHub API and JSON registries.
  • [DATA_EXFILTRATION]: No patterns of sensitive data access or unauthorized exfiltration to external domains were detected.
  • [PROMPT_INJECTION]: The skill carries a baseline risk of indirect prompt injection inherent to processing external API specifications.
  • Ingestion points: Fetches data from api.github.com, api.apis.guru, and raw.githubusercontent.com (SKILL.md).
  • Boundary markers: None present; the agent is instructed to rely on the fetched specification as the primary source of truth.
  • Capability inventory: Employs curl for network operations (SKILL.md).
  • Sanitization: Data is parsed as JSON, but the resulting content is incorporated into the agent's context without additional filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 11:49 AM
Security Audit — agent-trust-hub — klh-openapi-directory-first