openapi-directory-first
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches metadata and API specifications from
api.github.comandapi.apis.guru. These are well-known, authoritative sources for public API definitions and are considered safe for development purposes. - [COMMAND_EXECUTION]: The skill includes bash commands using
curlandpython3to filter and display API information. These scripts run locally and use the-cflag to process data from standard input, ensuring that remote content is treated as data rather than executable code. - [REMOTE_CODE_EXECUTION]: Automated alerts regarding remote code execution were found to be false positives. The commands identified involve piping JSON data into a local Python parsing script for visualization, which is a common and safe practice for processing API responses.
- [DATA_EXFILTRATION]: No patterns of sensitive data access or external transmission of private information were detected. The network activity is limited to retrieving public specifications.
Audit Metadata