update-readme
Pass
Audited by Gen Agent Trust Hub on Mar 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool for repository discovery, executing standard commands like ls, git ls-files, and rg to identify project languages and directory structure in modules/language-audit.md.\n- [EXTERNAL_DOWNLOADS]: The skill leverages the WebSearch tool to identify high-quality README exemplars from GitHub and other public sources to inform structural documentation refreshes.\n- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface (Category 8) by ingesting untrusted content from the web to guide README generation. 1. Ingestion points: WebSearch results (exemplars). 2. Boundary markers: Absent. 3. Capability inventory: Bash, Write, Edit. 4. Sanitization: Absent. While present, this risk is inherent to the primary research purpose and the behavior is constrained to documentation artifacts.\n- [SAFE]: All identified tool operations and data flows are consistent with the skill's stated purpose of documentation generation and repository analysis.
Audit Metadata