readme-maker

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious behavior or security violations were detected in the analyzed files.
  • [COMMAND_EXECUTION]: The skill utilizes shell search tools such as find, grep, and ls to scan project structures and inspect manifest files. This behavior is clearly scoped to its purpose of project discovery and does not involve executing arbitrary or dangerous commands.
  • [PROMPT_INJECTION]: The skill instructions emphasize grounding all generated content in actual repo evidence, explicitly forbidding the fabrication of APIs, scripts, or installation commands. This acts as a safeguard against generating misleading or potentially malicious instructions in documentation.
  • [SAFE]: While the skill processes untrusted data (source code and manifests) to generate README files, it incorporates a comprehensive validation framework (rules/validation.md) to ensure accuracy and prevent the inclusion of unverified information, effectively mitigating risks associated with indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 08:02 PM
Security Audit — agent-trust-hub — readme-maker