skills/pproenca/dot-skills/orval/Gen Agent Trust Hub

orval

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes processes for ingesting and transforming OpenAPI specifications (external, untrusted data).
  • Ingestion points: OpenAPI YAML/JSON files are targeted in orvalcfg-input-validation.md and adv-input-transformer.md.
  • Boundary markers: The skill recommends using validation (validation: true) to ensure schema integrity before processing.
  • Capability inventory: The generated code performs network operations (Axios/Fetch) and the generation process involves file writes.
  • Sanitization: The skill promotes strict type checking via Zod and OpenAPI schema validation to sanitize API responses at runtime.
  • [DYNAMIC_EXECUTION]: The skill guides users on implementing input and output transformers which involve dynamic script execution during the build process.
  • Runtime compilation/loading: Rules adv-input-transformer.md and adv-output-transformer.md show how to configure Orval to load and execute local TypeScript/JavaScript scripts to modify specifications or generated code. This is a standard feature of the Orval tool and is presented here for legitimate architectural purposes.
  • [DATA_EXPOSURE]: Documentation examples in mutator-custom-instance.md and mutator-token-refresh.md illustrate how to handle authentication tokens using standard browser APIs like localStorage. These are common development patterns for client-side applications and do not involve hardcoded secrets or unauthorized exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:48 AM
Security Audit — agent-trust-hub — orval