Back to skill

Security audit

api-contract-review

Security checks across malware telemetry and agentic risk

Overview

This skill is a focused API contract review guide with no executable code, persistence, credential handling, or hidden side effects.

Install this if you want agents to perform API compatibility and contract reviews. Be aware it may activate on broad API-review phrasing, so use a more explicit request when you want implementation, security, or architecture review instead.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill description includes broad auto-trigger phrases like 'review this API' and 'review the endpoint', which can easily overlap with ordinary code-review or design-review requests. This can cause unintended invocation of this skill, leading the agent to apply the wrong review framework, miss user intent, or inappropriately steer work away from a more suitable skill.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The 'When to use this skill' section mixes exact trigger phrases with broad contextual conditions like any new endpoint or schema change, without a clear precedence or boundary for auto-invocation. In an agentic system, this ambiguity can cause over-selection of the skill on routine engineering tasks, creating workflow confusion and potentially suppressing more relevant security, code-quality, or architecture reviews.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.