api-caller

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of HTTP requests via command-line scripts (scripts/call_api.py and scripts/parse_openapi.py).
  • These scripts take URLs and JSON strings as arguments and use standard Python libraries (urllib.request) to perform network operations.
  • The skill implements _validate_http_url in both scripts to ensure that only http and https schemes are allowed, mitigating risks associated with server-side request forgery (SSRF) or local file access via file:// schemes.
  • While the skill handles authentication headers, it correctly advises users to provide tokens as arguments rather than hardcoding them, and the evaluation examples follow safe practices for credential management.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 12:39 PM
Security Audit — agent-trust-hub — api-caller