skills/ben2pc/auriga-cli/docent/Gen Agent Trust Hub

docent

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Uses git to retrieve file history and logs, and executes a local script scripts/assemble.sh to build the final report. It also utilizes system commands like open to display the output.
  • [EXTERNAL_DOWNLOADS]: May download and execute the nomnoml package from the official NPM registry via npx to render software architecture diagrams.
  • [PROMPT_INJECTION]: Functions as an indirect prompt injection surface by processing local code and git metadata. The skill includes mitigation via structured report assembly and string escaping (html_escape and escapeXml) to prevent code injection in the HTML output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 03:03 AM
Security Audit — agent-trust-hub — docent