start-new-sdk-project

Pass

Audited by Gen Agent Trust Hub on Oct 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to use the official speakeasy CLI tool to generate SDKs and workflow configuration files. This is the primary function of the skill and aligns with the author's intent.
  • [EXTERNAL_DOWNLOADS]: The CLI tool supports fetching OpenAPI specifications from remote HTTPS URLs. This is a documented and expected feature for integrating with remote API definitions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided OpenAPI schemas from external sources. While OpenAPI specifications represent a potential surface for indirect prompt injection, this is a standard operational risk for SDK generators and is mitigated by the use of the vendor's specialized CLI tool.
  • [SAFE]: The skill demonstrates secure secret management by instructing users to use environment variables (SPEAKEASY_API_KEY) or interactive authentication rather than hardcoding sensitive credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 7, 2026, 11:45 AM