setup-demon-skills
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from repository files to identify existing documentation standards.
- Ingestion points: Reads
AGENTS.md,.agents/notes/,docs/i18n/, anddocs/AGENTS.md(SKILL.md). - Boundary markers: No explicit delimiters or warnings provided for processed data.
- Capability inventory: Performs file read and write operations.
- Sanitization: No input sanitization is performed, though the skill requires user confirmation before writing.
- [SAFE]: The skill's operations are limited to project documentation scaffolding. No network activity, credential access, or unauthorized system modifications were detected.
Audit Metadata