code-documenter
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The core workflow in
SKILL.mdrequires the agent to execute shell commands to validate documentation, includingpython -m doctest,pytest --doctest-modules, andtsc --noEmit. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because the
Validatestep inSKILL.mdexecutes code blocks extracted from project files. Ingestion points include any file processed during theDetectandAnalyzesteps, and there are no explicit sanitization or boundary markers defined to prevent the execution of malicious instructions embedded in those files. - [EXTERNAL_DOWNLOADS]: The skill uses
npxto execute@redocly/clifor OpenAPI validation and references the installation of various developer tools from public registries, includingpydocstyle,interrogate,linkchecker, andbroken-link-checker.
Audit Metadata