qa-api-testing-contracts
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external API artifacts such as OpenAPI specifications, GraphQL SDL, and Protobuf files, which can potentially contain malicious instructions embedded in documentation or example fields.
- Ingestion points: Canonical artifacts (OpenAPI, SDL, Proto, AsyncAPI, Arazzo) are identified and processed as described in the workflow section of SKILL.md.
- Boundary markers: There are no explicit instructions for the agent to use delimiters or specific ignore-instructions when processing these external artifacts.
- Capability inventory: The skill provides bash scripts that execute validation tools (Spectral, Buf, Schemathesis, Pact) against these artifacts.
- Sanitization: The provided scripts are thin wrappers and do not implement specific sanitization of the input artifacts before passing them to the underlying tools.
- [EXTERNAL_DOWNLOADS]: The
schemathesis_baseline.shscript utilizesuvxto fetch and run theschemathesispackage. This is a well-known service for property-based API testing, and the download is considered safe for its intended purpose within a CI/CD context. - [COMMAND_EXECUTION]: The skill provides several bash scripts (
scripts/) designed to be executed in CI environments. These scripts correctly use environment variables for configuration and include best practices likeset -euo pipefailto ensure robust execution.
Audit Metadata