docslime-init
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
docslimecommand-line utility to initialize (docslime init) and list (docslime list) documentation files in the local repository. These commands are essential to the skill's primary function of project scaffolding. - [INDIRECT_PROMPT_INJECTION]: The instructions require the agent to analyze the project's repository content and user-defined goals to tailor the documentation scaffold, which introduces a surface for indirect prompt injection from files within the repo.
- Ingestion points: Local file listing (
ls) and repository contents analyzed during the "Tailor the template" step (Step 3). - Boundary markers: No explicit delimiters or instructions are provided to the agent to disregard instructions potentially embedded within the repository files being analyzed.
- Capability inventory: The skill executes
docslimeCLI commands and has the ability to recommend the deletion or modification of markdown files within thedocs/directory. - Sanitization: The skill does not define specific sanitization or validation steps for the external project data it ingests.
Audit Metadata