documentation-guidelines

Pass

Audited by Gen Agent Trust Hub on Feb 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill establishes a benign workflow for maintaining project documentation.
  • [PROMPT_INJECTION]: No instructions were found that attempt to bypass safety filters or reveal system prompts. The skill follows its defined logic for documentation generation.
  • [DATA_EXFILTRATION]: The skill does not access sensitive files like SSH keys or environment variables, and it contains no network-related commands (curl, wget) to send data externally.
  • [REMOTE_CODE_EXECUTION]: There is no evidence of downloading external scripts or installing third-party packages at runtime.
  • [SAFE]: The skill ingests untrusted guidelines from the repository, creating a potential surface for indirect prompt injection. However, its capabilities are strictly limited to writing markdown documentation, posing no significant security risk. Ingestion points: docs/memories/DOCUMENTATION_GUIDELINES.md and docs/memories/FRONTEND_API_DOCUMENTATION_GUIDELINES.md. Boundary markers: Absent. Capability: File system write (documentation). Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 28, 2026, 04:54 AM