api-security-testing
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documents the functional workflow for a security testing tool ('strix') authored by the vendor ('usestrix'). All external resources, including the homepage (docs.strix.ai) and the CLI tool itself, trace back to the vendor's infrastructure.
- [SAFE]: Network operations and command execution patterns described (e.g., executing the
strixbinary with various flags) are strictly aligned with the skill's primary purpose of enumerating and testing API endpoints. - [SAFE]: Handling of sensitive data like authentication tokens is managed through placeholders in instructions, and the skill provides explicit advice on using files to keep secrets out of shell history.
- [SAFE]: The processing of external inputs such as OpenAPI schemas, GraphQL endpoints, and Postman collections is a standard operational requirement for the tool's intended use case in automated penetration testing.
Audit Metadata