start-new-sdk-project
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to use the official
speakeasyCLI tool to generate SDKs and workflow configuration files. This is the primary function of the skill and aligns with the author's intent. - [EXTERNAL_DOWNLOADS]: The CLI tool supports fetching OpenAPI specifications from remote HTTPS URLs. This is a documented and expected feature for integrating with remote API definitions.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided OpenAPI schemas from external sources. While OpenAPI specifications represent a potential surface for indirect prompt injection, this is a standard operational risk for SDK generators and is mitigated by the use of the vendor's specialized CLI tool.
- [SAFE]: The skill demonstrates secure secret management by instructing users to use environment variables (
SPEAKEASY_API_KEY) or interactive authentication rather than hardcoding sensitive credentials.
Audit Metadata