code-documenter

Warn

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill's 'Core Workflow' includes a 'Validate' step that instructs the agent to run shell commands such as python -m doctest, pytest --doctest-modules, tsc --noEmit, and npx @redocly/cli lint. The execution of pytest and doctest on external files enables the execution of the code logic within those files directly in the agent's environment.
  • [PROMPT_INJECTION]: The skill has two primary injection concerns. First, the metadata contains an inconsistency: the declared author is 'Jeffallan', which differs from the system-provided author context of 'Krypton-Kr36'. Second, the skill is susceptible to indirect prompt injection because it ingests untrusted user source code and API specifications (ingestion point). It lacks explicit boundary markers or sanitization logic to prevent the agent from inadvertently following instructions embedded in code comments or docstrings, which is a risk given the agent's capability to execute commands during the validation phase (capability inventory).
  • [EXTERNAL_DOWNLOADS]: The reference documentation suggests the installation and use of various third-party packages for linting, testing, and documentation generation, including pydocstyle and linkchecker for Python, and @redocly/cli and create-docusaurus for Node.js. These tools are downloaded from standard registries like npm and PyPI.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 08:52 PM
Security Audit — agent-trust-hub — code-documenter