generating-rest-apis

Pass

Audited by Gen Agent Trust Hub on Mar 13, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via API specifications. 1. Ingestion points: API specifications are read from the {baseDir}/api-specs/ directory. 2. Boundary markers: The instructions lack specific delimiters or warnings to ignore instructions embedded within the specifications. 3. Capability inventory: The skill has extensive filesystem access (Read, Write, Edit) and command execution capabilities (Bash). 4. Sanitization: There is no evidence of input validation or sanitization for the content of the API specifications.
  • [COMMAND_EXECUTION]: The skill uses a specialized tool Bash(api:rest-*) to generate project scaffolding and boilerplate code at runtime based on the provided specifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 13, 2026, 11:20 AM