openapi-directory-first
Fail
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches data from well-known public repositories and APIs. * Fetches API directories and specifications from GitHub (api.github.com, raw.githubusercontent.com) and the official APIs.guru API (api.apis.guru).
- [COMMAND_EXECUTION]: Utilizes shell commands to interact with the API directory. * Uses curl piped into python3 -c to search and filter API listings. The Python code is a static script provided in the skill body for JSON processing and does not execute the remote content itself. While it contains a placeholder (SEARCH_TERM) for the agent to use, the execution context remains controlled.
- [PROMPT_INJECTION]: Provides a surface for indirect prompt injection through external data processing. * Ingestion points: OpenAPI specification files (YAML) are downloaded and read from the APIs-guru/openapi-directory GitHub repository (SKILL.md). * Boundary markers: None. The skill does not provide instructions to the agent to ignore or isolate potentially malicious natural language instructions contained within the description fields of the OpenAPI specs. * Capability inventory: The agent uses the information found in the specs to generate code, design API requests, and provide documentation to the user (SKILL.md). * Sanitization: The skill does not specify any validation or sanitization steps for the downloaded YAML content before the agent processes it.
Recommendations
- HIGH: Downloads and executes remote code from: https://api.apis.guru/v2/list.json, https://api.github.com/repos/APIs-guru/openapi-directory/contents/APIs/{provider.com} - DO NOT USE without thorough review
Audit Metadata