api-security

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or high-risk command execution identified. The skill is purely instructional and focused on defensive security auditing.- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it is designed to analyze untrusted external data such as OpenAPI schemas, GraphQL SDLs, and source code PRs.
  • Ingestion points: Documented in SKILL.md (schemas, route decorators, PR diffs).
  • Boundary markers: None identified in the provided instructions.
  • Capability inventory: Analysis and report generation; no active command execution tools or network operations are defined within this skill.
  • Sanitization: No specific sanitization or filtering logic is specified for the ingested content. This surface is inherent to the skill's primary purpose of security analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 04:30 PM
Security Audit — agent-trust-hub — api-security