auto-docs

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a protocol for documentation generation from source code analysis, matching its intended purpose.
  • [SAFE]: The skill explicitly instructs the agent to omit real secrets from the generated environment-variable tables.
  • [SAFE]: The skill references the author's repository (github.com/HermeticOrmus/auto-docs-skills) for context, which is a legitimate resource.
  • [PROMPT_INJECTION]: The skill's ingestion of untrusted project code represents a potential surface for indirect prompt injection. Mitigation is provided by requiring human review before committing changes. Evidence Chain: 1. Ingestion points: local manifest files and source code; 2. Boundary markers: Absent; 3. Capability inventory: File system read and write operations; 4. Sanitization: Relies on user review.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 03:25 PM
Security Audit — agent-trust-hub — auto-docs