endpoint-validator
Pass
Audited by Gen Agent Trust Hub on Jun 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate code analysis and testing tasks related to API consistency and OpenAPI compliance without any unauthorized behaviors.\n- [COMMAND_EXECUTION]: The shell commands and Docker operations defined in the workflow are scoped to local repository discovery and API verification, which are appropriate for a developer-oriented validation tool.\n- [PROMPT_INJECTION]: The skill processes application source files (e.g., DataStructure.php, SaveRecordAction.php) which introduces a surface for indirect prompt injection. However, no malicious instructions were detected in the skill content, and the usage is consistent with its primary purpose of code review. Evidence: Ingestion points: DataStructure.php, SaveRecordAction.php (via Read/Grep); Boundary markers: Absent; Capability inventory: Bash tool access; Sanitization: Absent.
Audit Metadata