document-writer

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from an external codebase while possessing powerful tools like Bash and file modification capabilities.
  • Ingestion points: The agent is instructed to read existing project files, source code, and configurations to generate documentation (SKILL.md, Step 2; WORKFLOW.md, Step 2).
  • Boundary markers: There are no explicit instructions or delimiters telling the agent to disregard instructions or prompts that may be embedded within the codebase content it analyzes.
  • Capability inventory: The skill is granted access to high-impact tools such as Write, Edit, and Bash.
  • Sanitization: The instructions do not specify any sanitization, filtering, or validation of the content read from the codebase before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 05:28 PM
Security Audit — agent-trust-hub — document-writer