docs
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [SAFE]: No malicious behavior, such as credential theft, unauthorized network access, or persistence mechanisms, was identified. The skill implements user-confirmation gates for personas and tone, which enhances operational safety.
- [INDIRECT_PROMPT_INJECTION]: The skill processes existing documentation files to inform its generation, creating a surface where untrusted data could theoretically influence output. (1) Ingestion points: Project documentation folders such as docs/, documentation/, and content/docs/ (SKILL.md). (2) Boundary markers: Absent; the instructions do not specify the use of delimiters when reading external files. (3) Capability inventory: The skill is limited to writing markdown files and does not have network access or system command execution capabilities. (4) Sanitization: The skill does not specify any sanitization process for the content it reads from existing files.
- [DYNAMIC_EXECUTION]: The skill dynamically incorporates instructions from local simple-english and i-have-adhd skill files. This is a standard instructional composition pattern and does not involve the execution of binary code or scripts from untrusted external sources.
Audit Metadata