api-designer
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard guidance for API design, including resource naming, HTTP mapping, and status code strategies, aligning with industry best practices.
- [SAFE]: The use of project steering files (steering/*.md) is a legitimate mechanism for maintaining architectural and technical context across different AI agent interactions.
- [SAFE]: The file output requirements are restricted to local project directories (./design/api/), and there are no network operations or external data transmissions initiated by the skill.
- [PROMPT_INJECTION]: The skill reads external requirement documents to inform its design process, which is an intended functionality. While it lacks explicit boundary markers for these inputs, this is characteristic of documentation-analysis tools and does not represent a direct threat in this context. 1. Ingestion points: Reads files from steering/ and docs/requirements/ directories. 2. Boundary markers: Absent. 3. Capability inventory: Employs Read, Write, Edit, and Bash for document lifecycle management. 4. Sanitization: Not specified.
Audit Metadata