Add Admin API Endpoint
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill guides the agent to execute
pnpm test:singlewithin theghost/coredirectory to verify new API endpoints. This is a standard and expected part of the developer workflow for the Ghost project. - [SAFE]: The documentation emphasizes security best practices by requiring a mandatory
permissionsdefinition in all controller methods, preventing developers from creating unauthorized access points. - [SAFE]: The instructions and references utilize official vendor libraries (@tryghost/api-framework, @tryghost/validator, @tryghost/errors) and maintain consistency with the established file structure of the Ghost CMS repository.
- [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or remote code execution from unknown sources was detected in the skill's instructions or reference materials.
Audit Metadata