rest-api-conventions

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is composed of documentation, Java templates, and examples for REST API design. It includes a specific security recommendation to clamp pagination sizes in Spring Boot configuration to prevent resource exhaustion attacks.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies external project artifacts (OpenAPI specs, controllers, tests) as data sources for the agent to inspect. This presents a potential surface for indirect prompt injection if those files contain adversarial content. The risk is mitigated by the skill's requirement to follow specific predefined Java records and response envelopes. * Ingestion points: existing controllers, tests and OpenAPI (SKILL.md) * Boundary markers: Present
  • specific Java templates and JSON structures are mandated * Capability inventory: Agent file system modification capabilities * Sanitization: Absent (Evidence: SKILL.md 'Inspect existing controllers, tests and OpenAPI').
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:14 PM
Security Audit — agent-trust-hub — rest-api-conventions