aigw-contrib-add-api

Pass

Audited by Gen Agent Trust Hub on Apr 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a development guide for modifying local project files. It does not include instructions for external network access, credential handling, or privilege escalation.- [COMMAND_EXECUTION]: The skill references standard development build commands such as 'make apigen' and 'make codegen'. These are intended for use within the context of the envoyproxy/ai-gateway development environment and do not involve remote code execution from untrusted sources.- [INDIRECT_PROMPT_INJECTION]: The skill accepts user-provided arguments like 'FieldName' and 'FieldDescription' which are interpolated into Go templates. While these are technically ingestion points for untrusted data, the risk is minimal as the resulting code is subject to local compilation and testing via the 'make' commands described in the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 27, 2026, 11:55 AM
Security Audit — agent-trust-hub — aigw-contrib-add-api