codedocs

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and summarizes untrusted data from the target codebase to generate documentation.
  • Ingestion points: The skill performs a full recursive census and reads the contents of all source files (e.g., package.json, Cargo.toml, .ts, .py, .rs) to generate summaries, architecture overviews, and pattern documentation as described in references/generate-workflow.md.
  • Capability inventory: The agent has permissions to execute shell commands (git, ls) and perform extensive file system writes across multiple directories.
  • Boundary markers: The instructions do not provide delimiters or "ignore" directives to prevent the agent from following malicious prompts embedded within the source code files it is documenting.
  • Sanitization: The discovery and generation workflows lack explicit sanitization or validation of the contents retrieved from the repository before processing them.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to interact with the environment and analyze the codebase.
  • The "Companion check" in SKILL.md uses the ls command to search for installed extensions in platform-specific paths like ~/.claude/skills/, ~/.agent/skills/, and within the local project directory.
  • The update and generate workflows rely on git commands (e.g., git diff, git log, git ls-files) to identify project boundaries, compute coverage, and track changes between commits.
  • [EXTERNAL_DOWNLOADS]: The documentation encourages the use of npx to download and install the skill from the vendor's repository (AbsolutelySkilled/AbsolutelySkilled). This is a standard installation method for the platform but involves executing remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — codedocs