ln-21-documentation-auditor

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to verify documentation claims, such as help text and example syntax, by executing shell commands. Evidence: The 'Tool Routing' and 'Checklist' sections explicitly recommend using 'Shell in non-mutating or dry-run mode' and executing examples in 'safe local or disposable' contexts. While these constraints are safety-oriented, they establish a functional surface for command execution.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted input from source code comments and external documentation. \n
  • Ingestion points: Documentation entrypoints, code-comment surfaces, and external API specifications (SKILL.md). \n
  • Boundary markers: The skill does not prescribe the use of specific delimiters or 'ignore' instructions for the content being audited. \n
  • Capability inventory: The agent is granted capabilities to execute shell commands and perform broad repository searches (SKILL.md). \n
  • Sanitization: No sanitization or filtering of the audited content is required before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 04:08 AM
Security Audit — agent-trust-hub — ln-21-documentation-auditor