request-response

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of documentation, guidelines, and templates for API design. It does not contain any executable scripts, remote code downloads, or network operations.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill explicitly instructs developers to avoid returning sensitive information such as password hashes, internal IDs, or debugging information in API responses, which is a positive security practice.
  • [PROMPT_INJECTION]: No instructions were found that attempt to bypass safety filters, override agent behavior, or extract system prompts.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process API endpoint definitions (which could theoretically contain untrusted data), the skill itself only provides formatting and design guidance and lacks the capabilities (like shell execution or network requests) that would make such an injection exploitable.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 03:29 AM
Security Audit — agent-trust-hub — request-response