repository-documentation

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses Bash to execute gh CLI commands for updating repository metadata. Specifically, it runs gh repo edit --description and gh api repos/<owner>/<repo>/topics -X PUT to apply generated content to the GitHub repository. While these actions are central to the skill's purpose, they involve executing shell commands with strings synthesized from project data.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it reads and processes untrusted local project files to generate documentation.
  • Ingestion points: The skill reads root configuration files (e.g., package.json, app.json, pubspec.yaml) and deeply analyzes source code (e.g., src/index.ts, app/layout.tsx, feature directories) to understand the project's purpose, as detailed in Step 1 and Step 3b of SKILL.md.
  • Boundary markers: Absent. There are no instructions for the agent to use delimiters or ignore potential instructions embedded within the source files it analyzes.
  • Capability inventory: The skill possesses the capability to Write to the local README.md and execute shell commands via the gh CLI to modify remote repository metadata.
  • Sanitization: Absent. The instructions do not specify any sanitization or escaping of the data extracted from source files before it is interpolated into the documentation templates or passed as arguments to the gh CLI.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 03:50 PM
Security Audit — agent-trust-hub — repository-documentation