skills/jorgemuza/orbit/format-docs/Gen Agent Trust Hub

format-docs

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes user-controlled markdown files from the local filesystem to analyze, restructure, and format them.
  • Ingestion points: Processes markdown files and directory structures in the project as described in SKILL.md (Process steps 1 and 3).
  • Boundary markers: Absent. The agent is instructed to read and transform file content without specific delimiters or instructions to isolate potential malicious directives within the documents.
  • Capability inventory: The skill is capable of creating new files (INDEX.md), renaming files, and modifying file content including frontmatter, headings, and metadata blocks.
  • Sanitization: No specific content sanitization or instruction-filtering is identified; the focus is on structural formatting.
  • [DATA_EXFILTRATION]: The skill documentation references the use of the Kroki service for rendering diagrams.
  • Evidence: SKILL.md section 5 notes that diagrams are sent to https://kroki.io or a configured instance for conversion to images.
  • Context: This targets a well-known service for diagram-as-code rendering and is documented neutrally as a feature of the documentation workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 09:02 AM
Security Audit — agent-trust-hub — format-docs