generate-docs-from-source

Warn

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run repository-specific tests, build scripts, and lifecycle hooks (e.g., npm test) to verify documentation examples. This represents execution of arbitrary code found within the source repository.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8). Evidence chain: (1) Ingestion points: Files identified by rg --files and project manifests in the source repository; (2) Boundary markers: Absent; (3) Capability inventory: Shell command execution, file writing, and GitHub Action creation; (4) Sanitization: Absent.- [EXTERNAL_DOWNLOADS]: The skill configures documentation blocks and GitHub Actions that interact with external network origins or download remote resources, which may lead to unauthorized data access or execution of external logic if the source or configuration is malicious.- [DATA_EXFILTRATION]: The skill targets sensitive files such as environment examples and manifests for information gathering. While it warns against using real credentials, the processing of these files creates a surface for accidental exposure of sensitive information in the final documentation output.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 3, 2026, 06:18 PM
Security Audit — agent-trust-hub — generate-docs-from-source