api-testing
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines industry-standard testing procedures for REST APIs using Supertest and MSW. It does not contain any executable scripts or dangerous command patterns.
- [EXTERNAL_DOWNLOADS]: The documentation suggests the optional addition of a related skill from the same vendor ('oakoss') using the platform's standard 'npx skills add' command in SKILL.md. This is a legitimate extension mechanism for verified author resources.
- [INDIRECT_PROMPT_INJECTION]: The skill outlines patterns for testing APIs, which involves ingesting remote data from HTTP responses.
- Ingestion points: Data returned from API endpoints during tests as described in references/supertest-patterns.md and references/msw-handlers.md.
- Boundary markers: The skill encourages strict assertions on response status and structure.
- Capability inventory: The scope is limited to assertion frameworks in references/assertion-patterns.md with no access to dangerous system functions from the ingested data.
- Sanitization: The skill explicitly demonstrates and recommends Zod schema validation in references/assertion-patterns.md to verify and sanitize the structure of all API responses.
Audit Metadata