api-testing-patterns
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as a documentation and methodology repository for API testing. No malicious code, unauthorized network calls, or persistence mechanisms were detected.
- [CREDENTIALS_UNSAFE]: Authentication testing patterns correctly use variables and placeholders (e.g.,
${authToken},${expired}) rather than hardcoding actual credentials. Theconfig.jsonfile properly initializes sensitive fields to null. - [INDIRECT_PROMPT_INJECTION]: The skill documents a workflow for ingesting OpenAPI and GraphQL specifications to generate test cases. While this involves processing external data, the skill includes guidance on verifying results against live services and handling error scenarios, which aligns with standard development practices.
- [EXTERNAL_DOWNLOADS]: External references are limited to official schemas (json-schema.org) and the vendor's own documentation domain (agentic-qe.dev). These are legitimate resources used for configuration validation.
Audit Metadata