code-documenter

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has a primary workflow that involves ingesting untrusted source code and documentation to 'Test all code examples compile/run'. This creates an attack surface where malicious instructions or code blocks embedded in documentation (e.g., Python docstrings) are executed by the agent.
  • Ingestion points: Processes user-provided source files and markdown documentation (SKILL.md Core Workflow).
  • Boundary markers: None detected; the skill does not instruct the agent to ignore or delimit embedded code in a way that prevents execution.
  • Capability inventory: The skill utilizes shell commands (python, pytest, tsc, npx) capable of executing code found in processed files.
  • Sanitization: No sanitization or sandboxing of the code snippets is mentioned before execution.
  • [COMMAND_EXECUTION]: The core workflow instructions include the execution of several CLI tools: python -m doctest, pytest --doctest-modules, tsc --noEmit, and npx @redocly/cli lint (SKILL.md Step 5).
  • [DYNAMIC_EXECUTION]: The skill specifically instructs the agent to run code blocks extracted from local documentation files via doctest and pytest. This dynamic execution of content found within data files (code/docs) is a vector for local code execution.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to invoke the @redocly/cli for OpenAPI validation, which can trigger the download and execution of packages from the npm registry at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — code-documenter