api-contract-review

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository content, including source code, tests, and metadata. This provides an attack surface for indirect prompt injection where malicious instructions in those files could attempt to influence the agent's review or generated PRs.
  • Ingestion points: The agent is directed to read implementation files in mcp/src/tools/*, related tests, and generated metadata as defined in the scope and evidence phase of SKILL.md.
  • Boundary markers: The workflow requires mandatory verification against official documentation from cloud.tencent.com and docs.cloudbase.net, providing a logical integrity check against repository content.
  • Capability inventory: The skill empowers the agent to "prepare the code, test, and doc updates needed for a focused PR" based on its analysis results, which involves writing back to the filesystem (SKILL.md).
  • Sanitization: No specific content sanitization, escaping, or filtering mechanisms are documented for the ingested repository data.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — api-contract-review