readme-generate

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data by extracting text from project files and directly interpolating it into the generated documentation. This creates a surface for indirect prompt injection where malicious instructions in source files could influence subsequent AI processing of the generated README.\n
  • Ingestion points: The extract_module_info function in scripts/readme_generator.py reads the first paragraph from an existing README.md, and the analyze_controller function extracts text from Javadoc-style comments in .java files.\n
  • Boundary markers: The script does not implement delimiters or safety instructions to distinguish extracted external content from the generated documentation framework.\n
  • Capability inventory: The skill requires file system read permissions for the module directory and write permissions for the output documentation file.\n
  • Sanitization: No validation, escaping, or filtering of extracted strings was identified in the source code before they are written to the output file.\n- [COMMAND_EXECUTION]: The SKILL.md instructions guide the user or agent to execute a local Python script (scripts/readme_generator.py) using shell commands. This involves executing code that interacts with the local file system based on user-provided path arguments, which requires oversight to ensure inputs are trusted.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — readme-generate