code-documenter
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's core workflow includes instructions to execute shell commands for validating documentation examples and OpenAPI specifications. The agent uses these tools to confirm that the documented code actually runs as expected.
- Evidence: Use of
python -m doctest,pytest --doctest-modules,tsc --noEmit, andnpx @redocly/cli lintfor validation tasks. - [EXTERNAL_DOWNLOADS]: The documentation reference guides suggest the installation of several external packages and utilities from public registries such as npm and PyPI.
- Evidence: Mentions of installing
@redocly/cli,eslint-plugin-jsdoc,pydocstyle, andinterrogatefor documentation linting and coverage. - The use of
npx @redocly/cliinvolves downloading the package at runtime if it is not already present in the environment. - [PROMPT_INJECTION]: The skill processes untrusted user-provided source code to generate and validate documentation, which presents a surface for indirect prompt injection attacks.
- Ingestion points: The skill reads user source code and comments from the project files to extract documentation context (found in SKILL.md workflow).
- Boundary markers: The instructions lack explicit delimitation markers or warnings for the agent to ignore instructions that might be embedded within code comments or docstrings.
- Capability inventory: The agent has the capability to write files and execute shell commands (
python,npx,pytest) as part of its core documentation workflow (SKILL.md, references/coverage-reports.md). - Sanitization: There is no evidence of sanitization or filtering of the input code before it is processed or used in validation commands.
Audit Metadata