graphql-expert
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by generating application code (Python/TypeScript) based on user-supplied requirements. This creates a potential surface for indirect prompt injection if user-controlled data influences the generated logic.
- Ingestion points: User requirements for GraphQL schemas and resolver logic described in SKILL.md and processed by the agent.
- Boundary markers: The skill includes a 'Self-Check Checklist' and 'Anti-Hallucination Protocol' to enforce verification steps and boundary compliance.
- Capability inventory: The agent is instructed to write code, perform HTTP requests via libraries like httpx, and execute testing/type-checking tools (pytest, mypy).
- Sanitization: The instructions emphasize strict input validation using Zod and field-level authorization using graphql-shield as mandatory security practices.
- [SAFE]: The provided code examples and implementation workflows strictly follow security best practices. The skill includes a detailed mapping of GraphQL risks to the OWASP Top 10 2025 and provides concrete patterns to prevent SQL injection, information disclosure, and Denial of Service (DoS) through query complexity and depth limiting.
Audit Metadata