api-expert

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides extensive documentation on OWASP API Security Top 10 mitigations, including specific implementations to prevent Broken Object Level Authorization (BOLA), mass assignment, and Server-Side Request Forgery (SSRF).
  • [SAFE]: The 'Anti-Hallucination Protocol' enforces a security-first approach by requiring the agent to verify API specifications against official RFCs and OpenAPI standards before generating code, reducing the risk of implementing insecure or non-standard patterns.
  • [SAFE]: Code examples for authentication and authorization use industry-standard libraries (like RS256 for JWT) and include essential security measures such as token rotation, short-lived sessions, and scope-based access control.
  • [SAFE]: The skill advocates for the use of security scanning tools such as Bandit and OpenAPI validators, and emphasizes the filtering of sensitive fields (SSN, passwords) from API responses to prevent accidental data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:53 PM
Security Audit — agent-trust-hub — api-expert