docs-sync
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions focus on documentation maintenance and explicitly warn against pasting real credentials or production values into the documentation.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository, including code diffs, commits, and instructions, and utilizes repository tools for verification, such as linters and build scripts. Although this is a standard operational requirement for development tools, the instructions mitigate risks by requiring verification against the source of truth and discouraging the creation of new docs hierarchies that could bypass existing controls.
Audit Metadata