gateway
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is entirely composed of markdown files containing instructions and reference material. It does not include any scripts, executables, or code implementation, which significantly limits the attack surface.
- [SAFE]: The instructions prioritize robust API security, including mandatory OWASP API Security Top 10 compliance, OAuth 2.1 standards, and protection against BOLA (Broken Object Level Authorization) and BFLA (Broken Function Level Authorization).
- [SAFE]: No evidence of prompt injection, obfuscation, or data exfiltration was found across the 21 analyzed files. All instructional headers are standard and relevant to the skill's purpose.
- [SAFE]: While the skill involves reading existing project documentation and specifications (an indirect prompt injection surface), the lack of privileged capabilities such as arbitrary command execution or network exfiltration minimizes this risk.
- [SAFE]: No hardcoded credentials or sensitive file path access were detected. Recommendations for secret management follow best practices (e.g., using .env files).
Audit Metadata