code-documenter

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The core workflow in SKILL.md requires the agent to execute shell commands to validate documentation, including python -m doctest, pytest --doctest-modules, and tsc --noEmit.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because the Validate step in SKILL.md executes code blocks extracted from project files. Ingestion points include any file processed during the Detect and Analyze steps, and there are no explicit sanitization or boundary markers defined to prevent the execution of malicious instructions embedded in those files.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to execute @redocly/cli for OpenAPI validation and references the installation of various developer tools from public registries, including pydocstyle, interrogate, linkchecker, and broken-link-checker.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:18 PM
Security Audit — agent-trust-hub — code-documenter