dify-docs-write

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill incorporates a significant surface for indirect prompt injection by design. Ingestion points: The skill is instructed to read the target codebase to verify claims and specifically to adopt rules from an 'AGENTS.md' file if one exists in the target repository. Boundary markers: The instructions do not define clear delimiters or use 'ignore embedded instructions' warnings for content retrieved from external sources, which could allow malicious instructions in the codebase to influence the agent's behavior during the drafting or translation phases. Capability inventory: While the skill itself defines a workflow, it has the capability to invoke multiple specialized tools (including research, testing, and formatting skills) and to write content to documentation files and pull request descriptions. Sanitization: There is no mention of sanitizing, escaping, or validating the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 01:03 PM