api-security-testing

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains instructional shell commands using curl, jq, and grpcurl to interact with APIs. These commands are templates for security testing and use placeholders like URL and $TOKEN_LOW rather than hardcoded targets or credentials.
  • [DATA_EXFILTRATION]: No exfiltration patterns were detected. The network operations are limited to the target API under test for the purpose of identifying security vulnerabilities like Excessive Data Exposure (API3).
  • [SAFE]: The skill includes clear authorization warnings, advising users to only test APIs they own or are authorized to test, and to use non-production instances for stateful operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 09:03 PM
Security Audit — agent-trust-hub — api-security-testing