code-documenter

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to validate documentation and code examples. Specifically, it uses 'python -m doctest', 'pytest --doctest-modules', and 'tsc --noEmit' to ensure code blocks are functional and correctly typed.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the 'npx' command to run the Redocly CLI for OpenAPI linting and validation. Redocly is a well-known service providing tools for API documentation.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests untrusted source code and executes validation commands against that code. * Ingestion points: Reads various source code files (Python, TypeScript) and API specifications (OpenAPI/YAML) from the project filesystem (SKILL.md). * Boundary markers: The instructions do not define explicit delimiters or security warnings to distinguish between code logic and documentation content during processing. * Capability inventory: The skill has the capability to execute shell commands ('python', 'pytest', 'tsc', 'npx') as documented in the core workflow (SKILL.md). * Sanitization: No input validation or sanitization is performed on the files before they are processed by the validation tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:07 PM