k6-docs
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the
k6 x docsshell command to retrieve documentation topics, search for content, and map the documentation tree. - [INDIRECT_PROMPT_INJECTION]: The agent processes output from the
k6 x docscommand. This is an ingestion point for external data, which is a standard surface for indirect prompt injection, but the risk is assessed as low given the source is the official tool's local documentation. - Ingestion points: Output of shell commands
k6 x docs(SKILL.md) - Boundary markers: None specified for the agent to distinguish tool output from instructions.
- Capability inventory: Execution of
k6CLI commands (SKILL.md) - Sanitization: No explicit sanitization or filtering of the documentation content is performed before the agent processes it.
Audit Metadata