api-security

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is configured with a restricted toolset comprising only Read, Grep, and Glob, ensuring that the agent can only perform static analysis without the ability to execute code, modify files, or perform network operations.
  • [PROMPT_INJECTION]: A dedicated 'Prompt Injection Safety Notice' is included in SKILL.md which provides explicit directives to the agent to treat all reviewed content as inert text and to disregard any instructions or commands embedded within target files.
  • [INDIRECT_PROMPT_INJECTION]: The skill acknowledges the risk of processing untrusted external data (API specs and source code) and mitigates it through behavioral guardrails that prevent the interpretation or evaluation of content found in the analysis targets.
  • [DATA_EXFILTRATION]: No instructions or tools for external communication are present; the skill explicitly forbids the exfiltration of findings or code to any external service or URL mentioned in the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 01:49 PM
Security Audit — agent-trust-hub — api-security