doc-sync
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: LOWNO_CODE
Full Analysis
- [No Code Content] (INFO): The provided analysis input consists only of a metadata.json file. The functional skill logic, typically found in SKILL.md, is missing.
- [Trusted Source] (INFO): The author is identified as JetBrains, which is a recognized trusted organization. The GitHub repository URL matches the official JetBrains organization profile.
- [Indirect Prompt Injection Surface] (LOW): The description identifies a potential attack surface as the skill processes untrusted external content (documentation and code). Evidence Chain: (1) Ingestion points: doc/, README.md, CONTRIBUTING.md, and codebase files; (2) Boundary markers: Unknown due to missing code; (3) Capability: Synchronizing/modifying documentation and code (implies read/write); (4) Sanitization: Unknown. Given the trusted source and the absence of implementation code, this is noted as an architectural risk rather than an active vulnerability.
Audit Metadata