agents-md
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use standard shell commands such as
find,ls, andln -sto locate skill files within the project and manage documentation symlinks.\n- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill requires the agent to read content from locally discovered skill files to populate documentation templates.\n - Ingestion points:
SKILL.mdfiles located in project-specific directories like.claude/skills/orplugins/*/skills/(SKILL.md).\n - Boundary markers: Not present; the agent is directed to read discovered files directly to understand their purpose.\n
- Capability inventory: File discovery (
find,ls) and document creation/writing (AGENTS.md) in SKILL.md.\n - Sanitization: None; content is parsed as natural language instructions for documentation generation.
Audit Metadata