documentation-lookup

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is focused on documentation retrieval and does not contain instructions for accessing sensitive local files, hardcoded credentials, or performing unauthorized system modifications.\n- [SAFE]: It incorporates security best practices by explicitly requiring the redaction of secrets such as API keys and passwords before the agent sends queries to the external documentation tools.\n- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it fetches and processes content from external documentation sources. This is a low-risk surface inherent to the tool's intended purpose.\n
  • Ingestion points: External documentation text and code snippets retrieved via the query-docs tool.\n
  • Boundary markers: The instructions do not define specific delimiters for the external content.\n
  • Capability inventory: The skill provides documentation retrieval tools; the impact of potential injection depends on the agent's broader capabilities.\n
  • Sanitization: The skill relies on the agent to redact sensitive user data before querying the external service.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — documentation-lookup