documenter

Pass

Audited by Gen Agent Trust Hub on Apr 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection.
  • Ingestion points: Processes repository content, including code, configuration files, and existing documentation (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious embedded instructions in the source material.
  • Capability inventory: Instructed to validate claims by running or inspecting commands and examples found in the repository (SKILL.md).
  • Sanitization: No sanitization or validation of the ingested content is performed before the agent acts upon it.
  • [COMMAND_EXECUTION]: The skill grants the agent the authority to execute commands found within the project repository.
  • Evidence: The workflow explicitly directs the agent to 'run or inspect commands and examples when feasible' to validate documentation claims (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 26, 2026, 08:09 AM