api-designer
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior, obfuscation, or persistence mechanisms were detected. The skill follows industry best practices for API architecture documentation.
- [EXTERNAL_DOWNLOADS]: Mentions using
npxto execute@redocly/cliand@stoplight/prism-cli. These are recognized industry-standard tools for API lifecycle management. - [COMMAND_EXECUTION]: Instructs the agent to run CLI commands for linting, mocking, and SDK generation using standard tools such as
spectralandopenapi-generator-clifor their intended purposes. - [PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by ingesting and processing externally supplied OpenAPI specifications.
- Ingestion points: OpenAPI YAML/JSON files and business requirement documents provided by the user in the workspace.
- Boundary markers: None explicitly defined for isolating untrusted data input.
- Capability inventory: Command execution for API validation and mocking tools (
redocly,prism,spectral). - Sanitization: None explicitly defined in the instructions; relies on the internal validation logic of the referenced CLI tools.
Audit Metadata