repository-documentation
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
Bashto executeghCLI commands for updating repository metadata. Specifically, it runsgh repo edit --descriptionandgh api repos/<owner>/<repo>/topics -X PUTto apply generated content to the GitHub repository. While these actions are central to the skill's purpose, they involve executing shell commands with strings synthesized from project data. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it reads and processes untrusted local project files to generate documentation.
- Ingestion points: The skill reads root configuration files (e.g.,
package.json,app.json,pubspec.yaml) and deeply analyzes source code (e.g.,src/index.ts,app/layout.tsx, feature directories) to understand the project's purpose, as detailed in Step 1 and Step 3b ofSKILL.md. - Boundary markers: Absent. There are no instructions for the agent to use delimiters or ignore potential instructions embedded within the source files it analyzes.
- Capability inventory: The skill possesses the capability to
Writeto the localREADME.mdand execute shell commands via theghCLI to modify remote repository metadata. - Sanitization: Absent. The instructions do not specify any sanitization or escaping of the data extracted from source files before it is interpolated into the documentation templates or passed as arguments to the
ghCLI.
Audit Metadata