literate-programming
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were identified in the skill's instructions or referenced files. The logic is entirely focused on documentation and architectural analysis.\n- [PROMPT_INJECTION]: The skill instructions define a specialized analysis workflow without attempting to bypass safety guardrails or override system instructions. While the tool analyzes untrusted codebase files, which is a standard indirect injection surface (Ingestion points: codebase files in Step 1 and 3 of SKILL.md; Boundary markers: absent; Capability inventory: file reading and summarization; Sanitization: absent), this is part of its core intended functionality and does not represent a malicious instruction.\n- [DATA_EXFILTRATION]: No patterns of unauthorized data harvesting or external transmission were detected. File access is limited to the local project context for the purpose of architectural documentation and narration.\n- [REMOTE_CODE_EXECUTION]: The skill does not include mechanisms for downloading or running external code, scripts, or binaries. It relies on the agent's native ability to process and summarize text.
Audit Metadata