vision-forge
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is focused on documentation tasks and does not perform any network operations, command execution, or sensitive file access.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it reads repository documents. However, this is considered safe as the skill's capabilities are restricted to document generation and it includes guidance for agents to differentiate between intent and operational instructions.\n
- Ingestion points: Reads local project documentation including README.md, VISION.md, and project notes as described in SKILL.md.\n
- Boundary markers: Provides an example excerpt for AGENTS.md to explicitly define boundaries between intent and operational rules.\n
- Capability inventory: Limited to reading and writing project documentation files.\n
- Sanitization: None specified, as the skill produces human-readable documentation.
Audit Metadata