api-security
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or high-risk command execution identified. The skill is purely instructional and focused on defensive security auditing.- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it is designed to analyze untrusted external data such as OpenAPI schemas, GraphQL SDLs, and source code PRs.
- Ingestion points: Documented in SKILL.md (schemas, route decorators, PR diffs).
- Boundary markers: None identified in the provided instructions.
- Capability inventory: Analysis and report generation; no active command execution tools or network operations are defined within this skill.
- Sanitization: No specific sanitization or filtering logic is specified for the ingested content. This surface is inherent to the skill's primary purpose of security analysis.
Audit Metadata