api-security-testing
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for using the
strixCLI tool to perform automated security scans. It details various command-line arguments for targeting APIs via URLs, OpenAPI/Swagger specifications, Postman collections, and local source code directories. - [SAFE]: The instructions emphasize responsible security testing, advising the user to only scan targets they own and to obtain necessary credentials directly from the user rather than using hardcoded or fabricated secrets.
- [SAFE]: Best practices for credential management are encouraged, such as using the
--instruction-fileflag to avoid leaking sensitive tokens into shell history or version control systems. - [SAFE]: All external documentation and reference links point to the vendor's official domain (
docs.strix.ai) or recognized industry standards bodies (owasp.org).
Audit Metadata