skill-documentarian
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to execute various shell commands and scripts for repository maintenance, including
npm run sync:skills,bash scripts/generate-og-image.sh, and directory traversal loops usingsedandgrepfor validation. - [EXTERNAL_DOWNLOADS]: The documentation recommends the installation of system dependencies like
imagemagickvia Homebrew and references assets from well-known services such as Google Fonts. These are standard development practices and target trusted sources. - [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and processing documentation (SKILL.md, guides, references) from multiple other skill directories to sync them with a central website. This represents an attack surface where a malicious skill could include hidden instructions in its markdown or frontmatter to influence the documentarian's behavior.
- Ingestion points:
.claude/skills/*/SKILL.mdand associated subdirectories (references/,guides/,templates/,examples/). - Boundary markers: The skill uses basic escaping for angle brackets during MDX conversion, but lacks comprehensive delimiters to isolate processed content from its own instructions.
- Capability inventory: The skill has broad capabilities including file read/write access and the ability to execute shell commands.
- Sanitization: There is minimal sanitization beyond preventing MDX compilation errors, leaving the agent potentially susceptible to instructions embedded in the processed markdown data.
Audit Metadata