openapi-directory-first

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches metadata and API specifications from api.github.com and api.apis.guru. These are well-known, authoritative sources for public API definitions and are considered safe for development purposes.
  • [COMMAND_EXECUTION]: The skill includes bash commands using curl and python3 to filter and display API information. These scripts run locally and use the -c flag to process data from standard input, ensuring that remote content is treated as data rather than executable code.
  • [REMOTE_CODE_EXECUTION]: Automated alerts regarding remote code execution were found to be false positives. The commands identified involve piping JSON data into a local Python parsing script for visualization, which is a common and safe practice for processing API responses.
  • [DATA_EXFILTRATION]: No patterns of sensitive data access or external transmission of private information were detected. The network activity is limited to retrieving public specifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 01:12 PM
Security Audit — agent-trust-hub — openapi-directory-first