doc-generator
Pass
Audited by Gen Agent Trust Hub on Feb 26, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted source code files, creating a surface for indirect prompt injection.
- Ingestion points: Source code files in the
src/directory accessed viagrepandReadtools. - Boundary markers: None; the instructions do not include warnings to ignore instructions embedded in code comments.
- Capability inventory: The skill is authorized to use
Bash,Read, andWritetools. - Sanitization: No sanitization or filtering is performed on analyzed code content before processing.
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to rungrepand standard Node.js utilities likeeslintandtypedocto analyze and validate code documentation.
Audit Metadata