doc-coauthoring

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface as it ingests untrusted data from 'unstructured context dumps' (Stage 1) and 'referenced files or connected sources' (Stage 2) to draft and refine documentation. There are no explicit boundary markers or sanitization steps mentioned to prevent embedded instructions in these sources from hijacking the agent's execution flow, particularly during the automated 'reader testing' phase where content is passed to fresh agents.
  • [COMMAND_EXECUTION]: The skill is designed to perform file system operations, specifically reading, creating, and editing files (Stage 4). While these are core functions of a co-authoring tool, they represent a capability that could be misused if the agent is successfully targeted by an indirect prompt injection via the source materials it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 10:04 AM
Security Audit — agent-trust-hub — doc-coauthoring