docslime-init

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the docslime command-line utility to initialize (docslime init) and list (docslime list) documentation files in the local repository. These commands are essential to the skill's primary function of project scaffolding.
  • [INDIRECT_PROMPT_INJECTION]: The instructions require the agent to analyze the project's repository content and user-defined goals to tailor the documentation scaffold, which introduces a surface for indirect prompt injection from files within the repo.
  • Ingestion points: Local file listing (ls) and repository contents analyzed during the "Tailor the template" step (Step 3).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to disregard instructions potentially embedded within the repository files being analyzed.
  • Capability inventory: The skill executes docslime CLI commands and has the ability to recommend the deletion or modification of markdown files within the docs/ directory.
  • Sanitization: The skill does not define specific sanitization or validation steps for the external project data it ingests.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 07:33 PM
Security Audit — agent-trust-hub — docslime-init