documentation-engineer

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions are professional and focused on documentation accuracy. No malicious intent or bypass techniques were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes repository content, which is a known attack surface for indirect injection. 1. Ingestion points: Repository files and command outputs (via SKILL.md instructions). 2. Boundary markers: Absent. 3. Capability inventory: workspace-write access (metadata in SKILL.md). 4. Sanitization: Absent.
  • [METADATA_POISONING]: The 'model' field in metadata mentions a non-existent version ('gpt-5.3-codex-spark'), which is misleading but carries no security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 01:42 AM
Security Audit — agent-trust-hub — documentation-engineer