lov-repo2docs
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads software and dependencies from well-known external sources to perform its primary function.\n
- Fetches the
create-fumadocs-apputility from the NPM registry usingnpx.\n - Uses
git cloneto retrieve source code from GitHub repositories when a URL is provided as the source.\n - Instructs the user to install
vercelandPillowfor deployment and image optimization.\n- [COMMAND_EXECUTION]: Shell commands are executed to scaffold and build the documentation project.\n - The script
scripts/scaffold_docs.pyinvokesnpx create-fumadocs-appandpnpm buildviasubprocess.run().\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources, creating a potential attack surface for indirect prompt injection.\n - Ingestion points: The
scripts/inventory.pyscript reads the beginning of files to identify titles, and the agent reads entire file contents during the iterative authoring loop.\n - Boundary markers: The instructions do not define delimiters or explicit "ignore" directives to prevent the agent from following instructions embedded within the source files.\n
- Capability inventory: The skill possesses the ability to write to the file system (creating MDX pages) and execute build commands.\n
- Sanitization: No sanitization or filtering is performed on the content read from the source repositories before it is passed to the agent's context.\n- [DYNAMIC_EXECUTION]: The skill utilizes dynamic execution patterns to load external tools.\n
- Invokes
npxto fetch and execute thecreate-fumadocs-apppackage at runtime.
Audit Metadata