skills/maddhruv/absolute/api-testing/Gen Agent Trust Hub

api-testing

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command (ls) to check for the presence of recommended companion skills in specific local directories (e.g., ~/.claude/skills/). This is used solely for dependency verification within the agent's own ecosystem and does not access sensitive user or system data.
  • [PROMPT_INJECTION]: The skill is designed to process untrusted user-provided API specifications and test code, which presents a surface for indirect prompt injection. Ingestion points: User-provided API endpoints and logic. Boundary markers: None explicitly defined in the instructions to separate user data from agent commands. Capability inventory: The agent typically has file system and shell access to write and run tests. Sanitization: No specific sanitization or validation of user-provided code is specified, relying on the agent's internal safety guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 01:04 PM
Security Audit — agent-trust-hub — api-testing