docslime-kiss

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted documentation files from a project's docs/ directory, which serve as ingestion points for external data. The skill instructions do not specify boundary markers or sanitization procedures for this ingested content. Given the skill's capabilities include file reading, shell command execution (grep), and file patching, there is a risk that malicious instructions embedded within the documentation could influence the agent's behavior during the audit.
  • [COMMAND_EXECUTION]: The skill includes a grep command (grep -rn "LLM:" docs/) to search for specific template markers. This is a read-only operation restricted to the documentation directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 07:33 PM
Security Audit — agent-trust-hub — docslime-kiss