docs-writer

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured templates and guidelines for generating technical documentation such as READMEs, API references, and architecture overviews.
  • [COMMAND_EXECUTION]: Command-line snippets provided in the templates (e.g., npm install, git clone) are examples intended for inclusion in documentation and are not directed at the agent for execution.
  • [DATA_EXFILTRATION]: The instructions require the agent to read existing project files to verify accuracy. This behavior is restricted to the local environment and the intended purpose of documenting the codebase.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests data from local source files. Ingestion points: README.md, docs folder, and source files. Boundary markers: none specified. Capability inventory: file reads and globbing only. Sanitization: none specified. The risk is minimized by the skill's focus on descriptive documentation output.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:56 AM
Security Audit — agent-trust-hub — docs-writer