api-designer

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard guidance for API design, including resource naming, HTTP mapping, and status code strategies, aligning with industry best practices.
  • [SAFE]: The use of project steering files (steering/*.md) is a legitimate mechanism for maintaining architectural and technical context across different AI agent interactions.
  • [SAFE]: The file output requirements are restricted to local project directories (./design/api/), and there are no network operations or external data transmissions initiated by the skill.
  • [PROMPT_INJECTION]: The skill reads external requirement documents to inform its design process, which is an intended functionality. While it lacks explicit boundary markers for these inputs, this is characteristic of documentation-analysis tools and does not represent a direct threat in this context. 1. Ingestion points: Reads files from steering/ and docs/requirements/ directories. 2. Boundary markers: Absent. 3. Capability inventory: Employs Read, Write, Edit, and Bash for document lifecycle management. 4. Sanitization: Not specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 09:53 AM
Security Audit — agent-trust-hub — api-designer