context-documentation
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it is designed to ingest and process untrusted data from a software repository (source code, configuration files, and manifests) to generate documentation.
- Ingestion points: The skill instructs the agent to read various files throughout the repository, including
README.md,package.json,Dockerfile, and other source code files. - Boundary markers: The instructions do not specify the use of clear delimiters or boundary markers when the agent processes these external files.
- Capability inventory: The skill utilizes file-writing capabilities to generate the
CONTEXT.mdfile based on the analyzed content. - Sanitization: There are no explicit instructions for sanitizing or escaping content retrieved from the repository before it is summarized into the final document.
- [DATA_EXPOSURE_&_EXFILTRATION]: The skill requires access to structural and configuration files (like
package.jsonor database configs) to perform its primary function. However, it contains explicit safeguards: "NEVER expose secrets," "NEVER include secret values," and instructions to use variable placeholders (e.g.,JWT_SECRET) instead of actual credentials. These instructions align with best practices for automated documentation tools.
Audit Metadata