codedocs
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and summarizes untrusted data from the target codebase to generate documentation.
- Ingestion points: The skill performs a full recursive census and reads the contents of all source files (e.g., package.json, Cargo.toml, .ts, .py, .rs) to generate summaries, architecture overviews, and pattern documentation as described in references/generate-workflow.md.
- Capability inventory: The agent has permissions to execute shell commands (git, ls) and perform extensive file system writes across multiple directories.
- Boundary markers: The instructions do not provide delimiters or "ignore" directives to prevent the agent from following malicious prompts embedded within the source code files it is documenting.
- Sanitization: The discovery and generation workflows lack explicit sanitization or validation of the contents retrieved from the repository before processing them.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to interact with the environment and analyze the codebase.
- The "Companion check" in SKILL.md uses the ls command to search for installed extensions in platform-specific paths like ~/.claude/skills/, ~/.agent/skills/, and within the local project directory.
- The update and generate workflows rely on git commands (e.g., git diff, git log, git ls-files) to identify project boundaries, compute coverage, and track changes between commits.
- [EXTERNAL_DOWNLOADS]: The documentation encourages the use of npx to download and install the skill from the vendor's repository (AbsolutelySkilled/AbsolutelySkilled). This is a standard installation method for the platform but involves executing remote code.
Audit Metadata