docs
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
git log --oneline -20to understand recent project changes for documentation updates. This is a common and safe practice for development tools. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the codebase to generate documentation, which represents an injection surface.
- Ingestion points: Reads
README.md, configuration files (package.json,Cargo.toml), and source directories (SKILL.md). - Boundary markers: The instructions include a safeguard to "Focus on facts" and "Do not invent requirements," and provide an
Agent Context Guidethat instructs the agent to use a question tool if documentation conflicts with intent. - Capability inventory: Performs file system reads, file system writes within the
docs/directory, and limitedgitcommand execution. - Sanitization: No specific string sanitization is mentioned, but the workflow emphasizes factual extraction rather than open-ended execution.
Audit Metadata