api-design
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is purely instructional and does not contain any executable scripts, remote downloads, or hidden code. It provides high-quality guidance for API architecture following established industry standards.
- [PROMPT_INJECTION]: The skill is designed to process untrusted external data such as API specifications and pull request content during reviews. This represents a potential surface for indirect prompt injection, which is an inherent risk for skills performing code or design reviews. However, its capabilities are limited to text generation and maintaining a local decision log. 1. Ingestion points: External API definitions, pull request code, and GraphQL schemas. 2. Boundary markers: No specific delimiters are defined to separate user-provided content from system instructions. 3. Capability inventory: Generation of text-based API designs and writing architectural decisions to the .gsd/DECISIONS.md file. 4. Sanitization: The instructions do not specify any validation or sanitization of the input data.
Audit Metadata