hai-audit-docs-against-code

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns such as direct prompt injection, obfuscation, or data exfiltration were detected. The skill correctly defines implementation code as the authoritative source of truth.
  • [INDIRECT_PROMPT_INJECTION]: The skill inherently processes untrusted documentation and source code files, which constitutes a surface for indirect prompt injection attacks.
  • Ingestion points: root README, documentation files in docs/, and various code/contract files (OpenAPI, protobuf, TS types).
  • Boundary markers: The skill does not provide specific delimiters or instructions to ignore potential commands embedded within the documentation it audits.
  • Capability inventory: The skill utilizes file system read access and generates a report; no network access or arbitrary command execution is explicitly requested or used in the skill logic.
  • Sanitization: No sanitization or validation of the content read from the audited files is mentioned in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:50 AM
Security Audit — agent-trust-hub — hai-audit-docs-against-code