technical-writer

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied documentation, which creates an attack surface for indirect prompt injection if the analyzed documents contain malicious instructions.
  • Ingestion points: External documentation files such as READMEs, API guides, and tutorials as specified in the skill description.
  • Boundary markers: None identified; there are no instructions to the agent to treat the documentation content as untrusted data or to use delimiters to prevent command execution.
  • Capability inventory: None; the skill defines no custom scripts or tools and operates using the agent's default environment.
  • Sanitization: None identified; the skill does not specify any validation or filtering for the documentation it reviews.
  • [NO_CODE]: The skill consists exclusively of markdown documentation and YAML configuration. It does not include any scripts, binaries, or external package dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 01:11 PM
Security Audit — agent-trust-hub — technical-writer