api-documentation-sync
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a set of natural language instructions guiding the agent on how to perform API documentation synchronization. It does not include executable scripts, external dependencies, or network-enabled commands.
- [INDIRECT_PROMPT_INJECTION]: The skill involves reading and processing source code files from the user's project to extract API metadata. While this exposes a surface for indirect prompt injection (where malicious content in source code could attempt to influence the agent's behavior), the risk is inherent to the tool's primary purpose of code analysis. The instructions explicitly include a safeguard requiring user confirmation before the agent writes any output to the filesystem.
Audit Metadata