api-security
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is configured with a restricted toolset comprising only
Read,Grep, andGlob, ensuring that the agent can only perform static analysis without the ability to execute code, modify files, or perform network operations. - [PROMPT_INJECTION]: A dedicated 'Prompt Injection Safety Notice' is included in
SKILL.mdwhich provides explicit directives to the agent to treat all reviewed content as inert text and to disregard any instructions or commands embedded within target files. - [INDIRECT_PROMPT_INJECTION]: The skill acknowledges the risk of processing untrusted external data (API specs and source code) and mitigates it through behavioral guardrails that prevent the interpretation or evaluation of content found in the analysis targets.
- [DATA_EXFILTRATION]: No instructions or tools for external communication are present; the skill explicitly forbids the exfiltration of findings or code to any external service or URL mentioned in the analyzed files.
Audit Metadata