literate-programming

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were identified in the skill's instructions or referenced files. The logic is entirely focused on documentation and architectural analysis.\n- [PROMPT_INJECTION]: The skill instructions define a specialized analysis workflow without attempting to bypass safety guardrails or override system instructions. While the tool analyzes untrusted codebase files, which is a standard indirect injection surface (Ingestion points: codebase files in Step 1 and 3 of SKILL.md; Boundary markers: absent; Capability inventory: file reading and summarization; Sanitization: absent), this is part of its core intended functionality and does not represent a malicious instruction.\n- [DATA_EXFILTRATION]: No patterns of unauthorized data harvesting or external transmission were detected. File access is limited to the local project context for the purpose of architectural documentation and narration.\n- [REMOTE_CODE_EXECUTION]: The skill does not include mechanisms for downloading or running external code, scripts, or binaries. It relies on the agent's native ability to process and summarize text.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 12:15 PM