api-patterns

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides high-quality educational content on API design, authentication patterns, and security testing principles (e.g., OWASP API Top 10). The instructions and documentation contain no malicious patterns, obfuscation, or attempts to bypass safety filters.- [COMMAND_EXECUTION]: The skill defines a local command for executing a Python script scripts/api_validator.py. Analysis of this script confirms it is a legitimate static analysis tool that uses pathlib and re to scan for API patterns in local directories. It does not perform network operations, file writes, or dynamic code execution.- [INDIRECT_PROMPT_INJECTION]: The validation script reads external project files, which constitutes a potential indirect prompt injection surface where untrusted content could influence the agent's context. However, the risk is minimal due to the script's read-only nature and limited capabilities.
  • Ingestion points: scripts/api_validator.py reads content from files within a directory path provided by the user.
  • Boundary markers: None; the agent processes the script's findings without specific delimiters.
  • Capability inventory: The skill is restricted to file system read access and console output. It possesses no capabilities for data exfiltration, persistence, or privilege escalation.
  • Sanitization: The script uses regex patterns for analysis and does not evaluate or execute the content of the files it reads.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 08:28 PM
Security Audit — agent-trust-hub — api-patterns