api-security-testing
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of documentation and workflow instructions in markdown format. No executable scripts, binary files, or automated commands are included.
- [PROMPT_INJECTION]: Potential Indirect Prompt Injection Surface. The workflow involves the agent processing untrusted data from external APIs (e.g., error messages, documentation) which could contain embedded instructions.
- Ingestion points: API documentation review and error message testing in Phase 1 and Phase 7 (SKILL.md).
- Boundary markers: None specified in the workflow instructions.
- Capability inventory: The skill itself has no active capabilities but suggests invoking external tools for fuzzing and scanning.
- Sanitization: No explicit instructions for sanitizing or escaping external inputs before processing.
Audit Metadata