format-docs
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes user-controlled markdown files from the local filesystem to analyze, restructure, and format them.
- Ingestion points: Processes markdown files and directory structures in the project as described in SKILL.md (Process steps 1 and 3).
- Boundary markers: Absent. The agent is instructed to read and transform file content without specific delimiters or instructions to isolate potential malicious directives within the documents.
- Capability inventory: The skill is capable of creating new files (INDEX.md), renaming files, and modifying file content including frontmatter, headings, and metadata blocks.
- Sanitization: No specific content sanitization or instruction-filtering is identified; the focus is on structural formatting.
- [DATA_EXFILTRATION]: The skill documentation references the use of the Kroki service for rendering diagrams.
- Evidence: SKILL.md section 5 notes that diagrams are sent to
https://kroki.ioor a configured instance for conversion to images. - Context: This targets a well-known service for diagram-as-code rendering and is documented neutrally as a feature of the documentation workflow.
Audit Metadata