read-the-damn-docs

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary purpose is instructional, establishing a 'docs-first discipline' for agents to ensure accuracy when working with fast-moving APIs and libraries. No malicious intent or prompt injection attempts were identified.
  • [SAFE]: While the skill encourages fetching data from external web sources (documentation), it provides explicit guidelines to use authoritative and official sources (e.g., official API references, migration guides, and local repository docs). This minimizes the risk of indirect prompt injection typically associated with reading untrusted external content.
  • [SAFE]: The skill uses standard developer commands for informational purposes, such as npm view <pkg> version to verify package versions, which is a common and safe practice for ensuring compatibility.
  • [SAFE]: No sensitive data access, exfiltration patterns, or persistence mechanisms were found. The installation instructions in the README utilize a standard package manager and follow common patterns for skill deployment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:36 PM
Security Audit — agent-trust-hub — read-the-damn-docs