openapi-to-typescript

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a functional tool for developers to generate code from documentation. It lacks network connectivity, persistence mechanisms, or attempts to access sensitive system files.
  • [PROMPT_INJECTION]: The skill processes untrusted external data (OpenAPI files) which could potentially contain indirect prompt injection attempts within description fields or metadata. However, the conversion logic is highly structured and focuses on structural schema properties, which significantly limits the effectiveness of any natural language injection.
  • Ingestion points: OpenAPI JSON/YAML files provided by the user (SKILL.md, Workflow steps 1-2).
  • Boundary markers: The instructions do not specify explicit delimiters for data vs instructions within the processed file.
  • Capability inventory: The skill has file system read and write access for the purpose of processing the spec and saving the generated code.
  • Sanitization: No specific sanitization or filtering of text fields within the OpenAPI schema is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — openapi-to-typescript