skills/bastndev/skills/skrapi/Gen Agent Trust Hub

skrapi

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and summarize untrusted data from local project files (e.g., package.json, framework configs, and directory structures). This is a standard operational characteristic for code analysis tools.
  • Ingestion points: The skill reads package.json, framework-specific configurations (next.config.*, vite.config.*, etc.), and traversals of the project's directory tree to identify the tech stack.
  • Boundary markers: The instructions do not define specific delimiters or "ignore previous instructions" warnings when processing the contents of the analyzed project files.
  • Capability inventory: The agent is granted filesystem read access for project analysis and filesystem write access to create the SKRAPI/ documentation directory. It has no network access or shell execution capabilities.
  • Sanitization: There are no explicit sanitization or validation steps for the data retrieved from project files before it is incorporated into the generated documentation.
  • [SAFE]: The LICENSE.txt file contains a copyright notice for "Anthropic, PBC" despite the skill being authored by "bastndev". This is likely a result of using a template and does not impact the security or functionality of the skill, though it represents a metadata discrepancy.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 10:39 PM
Security Audit — agent-trust-hub — skrapi