api-sdk-generator

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides instructional templates for the agent to generate static source code files. It does not instruct the agent to execute dangerous shell commands, access sensitive system files, or establish unauthorized network connections. External references are directed at the official repository of a well-known software testing service.
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by processing external REST API specifications to generate code output.
  • Ingestion points: The agent ingests API resource definitions and structure provided by users or retrieved from external API specifications (SKILL.md).
  • Boundary markers: The skill does not specify the use of delimiters or clear markers to separate untrusted API data from the agent's generation instructions.
  • Capability inventory: The agent possesses the capability to write generated code to the local file system (SKILL.md).
  • Sanitization: The instructions do not mandate explicit validation or sanitization of the input API schema before code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 07:29 PM
Security Audit — agent-trust-hub — api-sdk-generator