skills/jmerta/codex-skills/docs-sync/Gen Agent Trust Hub

docs-sync

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions focus on documentation maintenance and explicitly warn against pasting real credentials or production values into the documentation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository, including code diffs, commits, and instructions, and utilizes repository tools for verification, such as linters and build scripts. Although this is a standard operational requirement for development tools, the instructions mitigate risks by requiring verification against the source of truth and discouraging the creation of new docs hierarchies that could bypass existing controls.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:45 PM
Security Audit — agent-trust-hub — docs-sync