technical-writer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an inherent attack surface for indirect prompt injection due to its core functionality of reading and validating project-specific documentation.
- Ingestion points: The
scripts/validate-docs.shutility is designed to scan and read the contents of various project files, includingREADME.md,CHANGELOG.md, and any markdown files located within documentation, API, and runbook directories. - Boundary markers: The skill lacks explicit boundary markers or instructions that would prompt the agent to disregard natural language commands found within the user-provided documentation files it processes.
- Capability inventory: The skill environment includes access to
Read,Write,Edit, andBashtools, which could be leveraged if an injection attack successfully manipulates the agent's execution flow during the validation process. - Sanitization: While the validation script uses standard shell tools (
grep,sed,find) for structural and content linting, it does not implement specific sanitization techniques to distinguish between legitimate documentation content and potential adversarial instructions.
Audit Metadata