api-designer

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious behavior, obfuscation, or persistence mechanisms were detected. The skill follows industry best practices for API architecture documentation.
  • [EXTERNAL_DOWNLOADS]: Mentions using npx to execute @redocly/cli and @stoplight/prism-cli. These are recognized industry-standard tools for API lifecycle management.
  • [COMMAND_EXECUTION]: Instructs the agent to run CLI commands for linting, mocking, and SDK generation using standard tools such as spectral and openapi-generator-cli for their intended purposes.
  • [PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by ingesting and processing externally supplied OpenAPI specifications.
  • Ingestion points: OpenAPI YAML/JSON files and business requirement documents provided by the user in the workspace.
  • Boundary markers: None explicitly defined for isolating untrusted data input.
  • Capability inventory: Command execution for API validation and mocking tools (redocly, prism, spectral).
  • Sanitization: None explicitly defined in the instructions; relies on the internal validation logic of the referenced CLI tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:51 PM
Security Audit — agent-trust-hub — api-designer