crafting-effective-readmes

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read project files (such as package.json, main source files, and existing README.md) to perform reviews and updates. This creates an attack surface where malicious instructions embedded in project metadata or code comments could potentially influence the agent's behavior.
  • Ingestion points: Reads local project files including package.json and source code.
  • Boundary markers: Not explicitly defined in the prompts.
  • Capability inventory: No dangerous tools or subprocess calls are invoked by this skill's instructions.
  • Sanitization: No specific sanitization or escaping of project file content is mentioned.
  • [CREDENTIALS_UNSAFE]: The templates/internal.md file contains placeholders for sensitive information like API_KEY and DATABASE_URL. These are provided solely as examples for documentation purposes and do not contain real secrets or instructions to leak them.
  • [EXTERNAL_DOWNLOADS]: The documentation and reference files (e.g., references/art-of-readme.md, references/standard-readme-spec.md) contain links to external GitHub repositories and documentation sites (such as hackergrrl/art-of-readme, makeareadme.com, and standard-readme). These are well-known community resources used for informational reference.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — crafting-effective-readmes