octocode-rfc-generator

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a vulnerability surface by ingesting data from external and potentially untrusted sources to generate documentation. Ingestion points include local source code, GitHub repository paths, pull requests, and commit history as specified in SKILL.md and README.md. The instructions do not define specific boundary markers, delimiters, or sanitization protocols for this ingested content. The skill possesses the capability to write durable markdown files to the .octocode/rfc/ directory, which could be exploited if malicious instructions in a pull request are processed and obeyed during document generation.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local utility script, scripts/eval-rfc.mjs, to validate the generated RFC artifacts. This script reads files from the local filesystem to perform regex-based quality checks against test cases defined in evals/cases.json. While the script can read any file the agent has access to via the --input flag, its functionality is limited to structural validation and it does not perform network operations or unauthorized data modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:42 AM
Security Audit — agent-trust-hub — octocode-rfc-generator