readme-writer
Pass
Audited by Gen Agent Trust Hub on Apr 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill follows best practices for project documentation generation.
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it reads and processes existing repository files (e.g., README.md, package.json) to generate content. However, the risk is negligible as the skill lacks high-impact tools like network exfiltration or shell execution, and its operations are restricted to documentation generation. -- Ingestion points: The skill reads existing README.md files and repository metadata via the Read tool. -- Boundary markers: No explicit delimiters or instruction-bypass warnings are defined in the workflow. -- Capability inventory: The skill utilizes Read, Grep, Write, and Edit operations. -- Sanitization: No sanitization of ingested file content is performed prior to processing.
Audit Metadata