docslime-kiss
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted documentation files from a project's
docs/directory, which serve as ingestion points for external data. The skill instructions do not specify boundary markers or sanitization procedures for this ingested content. Given the skill's capabilities include file reading, shell command execution (grep), and file patching, there is a risk that malicious instructions embedded within the documentation could influence the agent's behavior during the audit. - [COMMAND_EXECUTION]: The skill includes a
grepcommand (grep -rn "LLM:" docs/) to search for specific template markers. This is a read-only operation restricted to the documentation directory.
Audit Metadata