Skip to main content

api-writer

Assists in writing API contracts, ensuring clarity and compliance between teams during the development process.

Install this skill

or
74/100

Security score

The api-writer skill was audited on Jun 2, 2026 and we found 6 security issues across 1 threat category. Review the findings below before installing.

Categories Tested

Security Issues

medium line 3

Webhook reference - potential data exfiltration

SourceSKILL.md
3description: 'Write API contract, 写接口契约。Use when: PRD 完成后、HLD 之前需要定义 OpenAPI/AsyncAPI/GraphQL/gRPC/WebSocket/SSE/Webhook/SDK/文件格式规范。'
medium line 85

Webhook reference - potential data exfiltration

SourceSKILL.md
85- Webhook → `references/webhook-contract.md`
medium line 92

Webhook reference - potential data exfiltration

SourceSKILL.md
92当一个系统包含多种协议(如 REST + Webhook + WebSocket),**必须**:
medium line 126

Webhook reference - potential data exfiltration

SourceSKILL.md
126- HTTP / GraphQL / gRPC / Event / WebSocket-SSE / Webhook / SDK / File / IPC-CLI
low line 174

Webhook reference - potential data exfiltration

SourceSKILL.md
174- label: "Webhook"
medium line 217

Webhook reference - potential data exfiltration

SourceSKILL.md
217- `references/webhook-contract.md`
Scanned on Jun 2, 2026
View Security Dashboard
Installation guide →