octocode-rfc-generator
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits a vulnerability surface by ingesting data from external and potentially untrusted sources to generate documentation. Ingestion points include local source code, GitHub repository paths, pull requests, and commit history as specified in
SKILL.mdandREADME.md. The instructions do not define specific boundary markers, delimiters, or sanitization protocols for this ingested content. The skill possesses the capability to write durable markdown files to the.octocode/rfc/directory, which could be exploited if malicious instructions in a pull request are processed and obeyed during document generation. - [COMMAND_EXECUTION]: The skill instructs the agent to execute a local utility script,
scripts/eval-rfc.mjs, to validate the generated RFC artifacts. This script reads files from the local filesystem to perform regex-based quality checks against test cases defined inevals/cases.json. While the script can read any file the agent has access to via the--inputflag, its functionality is limited to structural validation and it does not perform network operations or unauthorized data modifications.
Audit Metadata