documentation
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run a local validation script using the command
node scripts/hooks/dispatcher.cjs stop. While this is intended for post-update verification, any execution of scripts within the project environment should be monitored for unexpected behavior. - [INDIRECT_PROMPT_INJECTION]: The skill operates by reading source code and updating files in the
docs/directory, which creates an attack surface where malicious instructions embedded in code could influence the agent. - Ingestion points: The agent reads source code and existing files within the
docs/directory to determine necessary updates. - Boundary markers: The instructions do not define clear delimiters or warnings to ignore instructions that may be embedded within the code being analyzed.
- Capability inventory: The skill has the ability to modify files in the
docs/directory and execute shell commands vianode. - Sanitization: No sanitization, filtering, or validation logic is specified for the code content before it is processed by the agent.
Audit Metadata