NYC

documentation-lookup

Warn

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection (MEDIUM): The skill handles untrusted external documentation that could contain instructions to override the agent's behavior.
  • Ingestion points: Content retrieved via the query-docs tool call in SKILL.md.
  • Boundary markers: Absent. No delimiters are defined to isolate untrusted documentation from the agent's instructions.
  • Capability inventory: The skill influences agent reasoning and generates code examples for the user based on fetched data.
  • Sanitization: Absent. No filtering or validation is performed on the documentation service's response.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 05:14 AM