documentation

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run a local validation script using the command node scripts/hooks/dispatcher.cjs stop. While this is intended for post-update verification, any execution of scripts within the project environment should be monitored for unexpected behavior.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by reading source code and updating files in the docs/ directory, which creates an attack surface where malicious instructions embedded in code could influence the agent.
  • Ingestion points: The agent reads source code and existing files within the docs/ directory to determine necessary updates.
  • Boundary markers: The instructions do not define clear delimiters or warnings to ignore instructions that may be embedded within the code being analyzed.
  • Capability inventory: The skill has the ability to modify files in the docs/ directory and execute shell commands via node.
  • Sanitization: No sanitization, filtering, or validation logic is specified for the code content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — documentation