crafting-effective-readmes

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No security issues were detected. The skill is an instructional tool composed of markdown templates and reference documentation for writing project READMEs.
  • [NO_CODE]: The skill does not include any scripts or executable code. It operates entirely through text instructions and templates for generating documentation content.
  • [DATA_EXPOSURE]: While templates like 'templates/internal.md' include placeholders for sensitive information such as 'DATABASE_URL' and 'API_KEY', these are documented as standard practices for what to include in internal documentation and do not contain or exfiltrate real credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted project data (e.g., 'package.json', existing README files) during the review process defined in 'SKILL.md'. However, because the skill lacks dangerous capabilities such as command execution, arbitrary file writes, or network exfiltration, the presence of this ingestion surface does not represent a significant threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — crafting-effective-readmes