skills/srstomp/pokayokay/api-testing/Gen Agent Trust Hub

api-testing

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOW
Full Analysis
  • [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials, sensitive file paths, or unauthorized network operations were found in the skill content.
  • [Remote Code Execution] (SAFE): No remote script downloads or arbitrary command execution patterns were detected.
  • [Prompt Injection] (SAFE): No instructions attempting to override agent behavior or bypass safety filters are present.
  • [Indirect Prompt Injection] (INFO): The skill outlines a workflow for processing external API responses and OpenAPI specifications. 1. Ingestion points: API response bodies and contract schemas. 2. Boundary markers: None specified in documentation. 3. Capability inventory: The skill references testing tools (Supertest, Vitest) that perform network requests. 4. Sanitization: No sanitization methods are discussed. While this defines an attack surface, no malicious implementation is provided.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 02:26 AM