technical-writer

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses platform-specific ! syntax in SKILL.md to load internal protocols and project configurations into the agent's context during initialization.
  • Evidence: Commands such as !cat skills/_shared/protocols/ux-protocol.md and !cat .production-grade.yaml are executed at skill load.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: Phase 4 of the skill workflow recommends installing standard NPM packages from the official registry to build a documentation site.
  • Evidence: The skill lists @docusaurus/core, @docusaurus/preset-classic, @docusaurus/theme-search-algolia, and other well-known dependencies in the generated package.json.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the repository (git logs and source code comments) to generate user-facing text, creating a surface for potential instruction injection.
  • Ingestion points: Commit history logs processed in phases/05-changelog.md and code comments analyzed in phases/01-content-audit.md.
  • Boundary markers: No explicit delimiters or instructions are used to separate the ingested data from the agent's control logic.
  • Capability inventory: The agent has permissions to read from the codebase and write to the local filesystem (docs/, CHANGELOG.md).
  • Sanitization: No explicit filtering or sanitization of the input text is mentioned in the documentation generation phases.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — technical-writer