design-api-stories

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional markdown files and example documentation. No scripts, binaries, or remote dependencies are present.
  • [PROMPT_INJECTION]: The skill processes external text data from requirements and domain models. This creates an indirect prompt injection surface, though the impact is negligible due to the lack of dangerous tools or system access. 1. Ingestion points: Requirements, Domain, and API Standards documents defined in Step 1. 2. Boundary markers: Absent. 3. Capability inventory: File-system write access for saving generated stories (Step 5). 4. Sanitization: No input validation or escaping is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 09:16 PM
Security Audit — agent-trust-hub — design-api-stories