api-contract-testing

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of Markdown instructions and YAML configuration files. There are no executable scripts (Python, JavaScript, shell) included in the package.
  • [SAFE]: The instructions promote security best practices, such as explicitly advising against unauthorized production writes, using least privilege, and utilizing masked data or dry runs for production/security work.
  • [PROMPT_INJECTION]: No evidence of prompt injection, jailbreak attempts, or system prompt extraction instructions were found. The 'Core Constraints' and 'Execution Rules' are focused on domain-specific quality bars and logic.
  • [DATA_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or network exfiltration patterns were detected. The skill operates within the context provided by the user.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (OpenAPI schemas, traffic samples), it includes strong boundary markers and instructions to separate facts from assumptions and to audit input credibility, which mitigates the risk of following malicious instructions embedded in that data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:26 AM
Security Audit — agent-trust-hub — api-contract-testing