auto-docs
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a protocol for documentation generation from source code analysis, matching its intended purpose.
- [SAFE]: The skill explicitly instructs the agent to omit real secrets from the generated environment-variable tables.
- [SAFE]: The skill references the author's repository (github.com/HermeticOrmus/auto-docs-skills) for context, which is a legitimate resource.
- [PROMPT_INJECTION]: The skill's ingestion of untrusted project code represents a potential surface for indirect prompt injection. Mitigation is provided by requiring human review before committing changes. Evidence Chain: 1. Ingestion points: local manifest files and source code; 2. Boundary markers: Absent; 3. Capability inventory: File system read and write operations; 4. Sanitization: Relies on user review.
Audit Metadata