readme-generate
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data by extracting text from project files and directly interpolating it into the generated documentation. This creates a surface for indirect prompt injection where malicious instructions in source files could influence subsequent AI processing of the generated README.\n
- Ingestion points: The
extract_module_infofunction inscripts/readme_generator.pyreads the first paragraph from an existingREADME.md, and theanalyze_controllerfunction extracts text from Javadoc-style comments in.javafiles.\n - Boundary markers: The script does not implement delimiters or safety instructions to distinguish extracted external content from the generated documentation framework.\n
- Capability inventory: The skill requires file system read permissions for the module directory and write permissions for the output documentation file.\n
- Sanitization: No validation, escaping, or filtering of extracted strings was identified in the source code before they are written to the output file.\n- [COMMAND_EXECUTION]: The
SKILL.mdinstructions guide the user or agent to execute a local Python script (scripts/readme_generator.py) using shell commands. This involves executing code that interacts with the local file system based on user-provided path arguments, which requires oversight to ensure inputs are trusted.
Audit Metadata