api-security

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is intended to ingest and analyze untrusted files such as source code and API specifications. It mitigates the risk of indirect prompt injection by including a 'Prompt Injection Safety Notice' that explicitly instructs the agent to treat all processed content as inert text and to ignore any directives found within analyzed data. Additionally, the skill's capabilities are limited to non-executing tools.
  • [COMMAND_EXECUTION]: No dangerous command execution patterns or shell injections were identified. The skill is restricted to using static analysis tools (Read, Grep, Glob) for reviewing file content, and the instructions prioritize static review over code execution.
  • [DATA_EXFILTRATION]: The skill lacks network access capabilities and does not contain any exfiltration patterns. The instructions explicitly forbid the agent from sending findings or source code to external services or URLs found within the target files.
  • [EXTERNAL_DOWNLOADS]: All external links provided in the documentation point to reputable and trusted resources, including official OWASP projects, NIST, and Microsoft documentation. There are no patterns involving the download or execution of remote scripts or unverified third-party code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:06 AM
Security Audit — agent-trust-hub — api-security