docent
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Uses
gitto retrieve file history and logs, and executes a local scriptscripts/assemble.shto build the final report. It also utilizes system commands likeopento display the output. - [EXTERNAL_DOWNLOADS]: May download and execute the
nomnomlpackage from the official NPM registry vianpxto render software architecture diagrams. - [PROMPT_INJECTION]: Functions as an indirect prompt injection surface by processing local code and git metadata. The skill includes mitigation via structured report assembly and string escaping (
html_escapeandescapeXml) to prevent code injection in the HTML output.
Audit Metadata