docs-init
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill demonstrates legitimate documentation management functionality with no evidence of malicious intent, obfuscation, or safety bypass attempts.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection through the ingestion of external project data. Ingestion points: The skill reads project documentation files in
docs/project-reference/and configuration fromdocs/project-config.json. Boundary markers: Absent; no specific delimiters or instructions to ignore embedded commands within the scanned files are provided. Capability inventory: Local file reading, user interaction, and invocation of other scanning skills (e.g.,/scan-*). Sanitization: Absent; no validation or filtering of input file content is specified. - [COMMAND_EXECUTION]: The workflow orchestrates the execution of multiple platform-specific scanning skills based on the identified state of the project documentation.
Audit Metadata