dev-loop-readme-writer

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured guidelines and templates for creating documentation. While it includes extensive reference files with repetitive technical content, no malicious code, prompt injections, or unauthorized network behaviors were found.
  • [DATA_EXPOSURE_EXFILTRATION]: The Python implementation patterns included in the skill body for metadata extraction are restricted to reading standard project files like package.json and Cargo.toml. No commands for sensitive data access or external exfiltration were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill's architecture for reading project metadata (Category 8) has a low risk profile as it targets structured files (package.json) and is used for generating static documentation. The capability surface is minimal and appropriate for its stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 12:22 PM
Security Audit — agent-trust-hub — dev-loop-readme-writer