frontend-data-contracts
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is entirely documentation-based and does not include any executable code or scripts.
- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for processing data from external APIs. Ingestion points: The apiClient fetch wrapper in shared/api-client/ as described in SKILL.md. Boundary markers: The skill mandates a 'Parse, don't validate' step using schema libraries to transform wire JSON into domain types. Capability inventory: No scripts or active capabilities are provided in this documentation-only skill. Sanitization: Zod/Valibot schema transformation is enforced at the network boundary.
- [SAFE]: No evidence of prompt injection, obfuscation, or data exfiltration attempts was found in the content or metadata.
Audit Metadata