repository-readme-writer
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from local repositories (such as scripts and manifests) to generate documentation, creating a potential surface for malicious instructions to be ingested into the agent's context.\n
- Ingestion points: Metadata and script content from
package.json,pyproject.toml, and other manifest files read byscripts/repo_readme_probe.pyduring repository analysis.\n - Boundary markers: The instructions do not define strict delimiters for the probe output, but the
SKILL.mdinstructions explicitly direct the agent to avoid verbatim assumptions from the repository in its Operating Contract.\n - Capability inventory: The skill performs local script execution and file reads to inventory the repository, then outputs generated README content.\n
- Sanitization: The instructions emphasize translating source tree details into high-level project boundaries and roles, which provides a layer of semantic abstraction over the raw repository data.\n- [COMMAND_EXECUTION]: The skill requires the agent to execute bundled Python scripts to perform repository audits.\n
- The agent is instructed to run
python3 scripts/repo_readme_probe.py <repo>to inventory repository signals as part of its primary workflow.\n - The
scripts/test_skill.pyutility usessubprocess.runwith list-based arguments to safely execute the probe script during development testing, avoiding shell injection risks.
Audit Metadata