skills/bulls-cows/skills/yy-vitepress/Gen Agent Trust Hub

yy-vitepress

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by processing external project files.
  • Ingestion points: The agent reads .vitepress/config.ts and package.json to locate source directories and path aliases.
  • Boundary markers: The instructions lack markers or warnings to disregard instructions found within the project configuration or source files.
  • Capability inventory: The skill possesses read capabilities for configuration files and write capabilities for project source files to insert documentation markers.
  • Sanitization: No sanitization or validation logic is defined for the content extracted from the external project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 08:08 AM
Security Audit — agent-trust-hub — yy-vitepress