dev-api-design
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The GitHub Actions template in
assets/oasdiff-ci.ymlfetches an installation script from the Tufin organization's official GitHub repository atraw.githubusercontent.com/tufin/oasdiff/main/install.shand executes it via a shell pipe. This is a standard method for installing the oasdiff utility used by the skill for breaking-change detection. - [EXTERNAL_DOWNLOADS]: The skill's templates for various frameworks (FastAPI, Express, Spring Boot) define dependencies to be fetched from official package registries such as npm, PyPI, and Maven. These downloads target well-known open-source libraries and services.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface in
references/llm-agent-api-contracts.mdrelated to APIs consumed by LLM agents. - Ingestion points: Data enters the system via API request bodies defined in framework templates (e.g.,
assets/fastapi/fastapi-complete-api.md). - Boundary markers: The templates utilize Pydantic and Zod schemas to define strict request boundaries.
- Capability inventory: The skill includes capabilities for database interaction (via SQLAlchemy or Prisma) and network requests.
- Sanitization: Content is validated against declared schemas before processing, providing significant protection against malformed input.
Audit Metadata