api-documentation-generator

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates the analysis of external codebase data which acts as an ingestion point for untrusted content. \n
  • Ingestion points: The skill analyzes source code, routes, and request structures from the user's workspace to generate documentation (SKILL.md). \n
  • Boundary markers: There are no explicit instructions for the agent to distinguish between code logic and potential instructions embedded in code comments, which could allow for indirect prompt injection. \n
  • Capability inventory: The skill's documented capabilities are limited to reading local files and generating markdown text; no high-risk capabilities like network access or arbitrary command execution are utilized. \n
  • Sanitization: The skill does not implement specific sanitization or escaping mechanisms for the data extracted from the analyzed codebase before it is incorporated into the output documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — api-documentation-generator