context-documentation

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it is designed to ingest and process untrusted data from a software repository (source code, configuration files, and manifests) to generate documentation.
  • Ingestion points: The skill instructs the agent to read various files throughout the repository, including README.md, package.json, Dockerfile, and other source code files.
  • Boundary markers: The instructions do not specify the use of clear delimiters or boundary markers when the agent processes these external files.
  • Capability inventory: The skill utilizes file-writing capabilities to generate the CONTEXT.md file based on the analyzed content.
  • Sanitization: There are no explicit instructions for sanitizing or escaping content retrieved from the repository before it is summarized into the final document.
  • [DATA_EXPOSURE_&_EXFILTRATION]: The skill requires access to structural and configuration files (like package.json or database configs) to perform its primary function. However, it contains explicit safeguards: "NEVER expose secrets," "NEVER include secret values," and instructions to use variable placeholders (e.g., JWT_SECRET) instead of actual credentials. These instructions align with best practices for automated documentation tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 06:35 PM
Security Audit — agent-trust-hub — context-documentation