documentation-writer

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structural and stylistic guidelines for technical writing. It does not include any commands for network access, remote code execution, or persistence mechanisms.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it is designed to ingest and process codebase content to generate documentation.
  • Ingestion points: Reads files and searches codebases (SKILL.md).
  • Boundary markers: Absent; the instructions do not specify how to handle embedded instructions in the source code.
  • Capability inventory: Includes the ability to write and edit files (SKILL.md).
  • Sanitization: Absent; the skill does not explicitly filter content from the source code.
  • Analysis: While the surface exists, this behavior is central to the skill's primary purpose and no specific exploitable patterns are provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 02:37 PM
Security Audit — agent-trust-hub — documentation-writer