repository-readme-writer

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from local repositories (such as scripts and manifests) to generate documentation, creating a potential surface for malicious instructions to be ingested into the agent's context.\n
  • Ingestion points: Metadata and script content from package.json, pyproject.toml, and other manifest files read by scripts/repo_readme_probe.py during repository analysis.\n
  • Boundary markers: The instructions do not define strict delimiters for the probe output, but the SKILL.md instructions explicitly direct the agent to avoid verbatim assumptions from the repository in its Operating Contract.\n
  • Capability inventory: The skill performs local script execution and file reads to inventory the repository, then outputs generated README content.\n
  • Sanitization: The instructions emphasize translating source tree details into high-level project boundaries and roles, which provides a layer of semantic abstraction over the raw repository data.\n- [COMMAND_EXECUTION]: The skill requires the agent to execute bundled Python scripts to perform repository audits.\n
  • The agent is instructed to run python3 scripts/repo_readme_probe.py <repo> to inventory repository signals as part of its primary workflow.\n
  • The scripts/test_skill.py utility uses subprocess.run with list-based arguments to safely execute the probe script during development testing, avoiding shell injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:51 AM
Security Audit — agent-trust-hub — repository-readme-writer