code-documenter

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill functions as a technical documentation assistant. All analyzed instructions and reference materials are legitimate and focused on software documentation best practices.
  • [EXTERNAL_DOWNLOADS]: The reference files mention several industry-standard tools for documentation generation and linting, such as Docusaurus, MkDocs, pydocstyle, and interrogate. These references are informative and point to trusted packages and repositories.
  • [PROMPT_INJECTION]: Indirect prompt injection surface analysis:
  • Ingestion points: The skill processes code files and API specifications provided by the user (as defined in the workflow in SKILL.md).
  • Boundary markers: No explicit boundary markers or 'ignore' instructions are defined for the input content.
  • Capability inventory: The skill primarily generates text and documentation; no dangerous system capabilities, subprocess calls, or arbitrary network operations are present in the scripts.
  • Sanitization: No explicit sanitization of input content is described. Given the purely descriptive nature of the skill and lack of hazardous capabilities, the overall risk is minimal.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 07:07 AM
Security Audit — agent-trust-hub — code-documenter