doc-generator

Pass

Audited by Gen Agent Trust Hub on Feb 26, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted source code files, creating a surface for indirect prompt injection.
  • Ingestion points: Source code files in the src/ directory accessed via grep and Read tools.
  • Boundary markers: None; the instructions do not include warnings to ignore instructions embedded in code comments.
  • Capability inventory: The skill is authorized to use Bash, Read, and Write tools.
  • Sanitization: No sanitization or filtering is performed on analyzed code content before processing.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to run grep and standard Node.js utilities like eslint and typedoc to analyze and validate code documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 26, 2026, 01:36 PM