dify-docs-guides
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a style guide and operational manual for documenting Dify's user guides. It defines reader personas and content structures for various deployment environments (Cloud vs. Self-hosted).\n- [DATA_EXPOSURE]: The skill suggests using
grepto search for feature keywords in files such asdocker/.env.exampleandapi/configs/. While these paths are sensitive, the operation is limited to identifying configuration keys for documentation purposes within the local environment and does not involve exfiltrating data to external domains.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes documentation paths and codebase content to generate drafting guidance. While this creates a potential surface for instructions embedded in data to influence the agent, the risk is minimal as the skill is focused on generating technical documentation rather than executing logic based on that data.
Audit Metadata