api-error-design
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists exclusively of markdown instructions and reference examples. There are no scripts, binaries, or command execution patterns present in the files.
- [DATA_EXPOSURE]: The guidelines explicitly warn against exposing sensitive information, such as stack traces, database internal errors, or system configuration paths, in API response bodies. This promotes a positive security posture for developers using the skill.
- [INDIRECT_PROMPT_INJECTION]: Although the skill is designed to process external inputs (real production error responses) to perform audits, it lacks any high-privilege capabilities such as file system writing, network requests, or shell execution, ensuring that malicious inputs cannot trigger harmful actions.
- [REMOTE_CODE_EXECUTION]: There are no patterns of remote code fetching or execution. References to other skills (e.g., samber/developer-platform-skills@...) are treated as vendor-owned resource pointers and do not involve code execution.
Audit Metadata