write-yard-docs

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run yard stats --list-undoc and yard doc. These are standard, well-known commands for the YARD documentation tool in Ruby development environments, used to verify documentation coverage and generate local API documentation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and modify Ruby source code, which constitutes an ingestion point for untrusted data that could contain indirect prompt injections. However, the instructions focus on structured documentation generation using specific tags (@param, @return, @raise), which limits the impact of potentially malicious content in the source code.
  • Ingestion points: Ruby source code files identified for documentation (mentioned in SKILL.md).
  • Boundary markers: No specific delimiters for the ingested code are defined in the skill instructions.
  • Capability inventory: The skill uses yard CLI tools and has the ability to write documentation comments back to the source files.
  • Sanitization: No explicit sanitization or filtering of the code content is described before documentation is generated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:22 PM
Security Audit — agent-trust-hub — write-yard-docs