crafting-effective-readmes
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read project files (such as
package.json, main source files, and existingREADME.md) to perform reviews and updates. This creates an attack surface where malicious instructions embedded in project metadata or code comments could potentially influence the agent's behavior. - Ingestion points: Reads local project files including
package.jsonand source code. - Boundary markers: Not explicitly defined in the prompts.
- Capability inventory: No dangerous tools or subprocess calls are invoked by this skill's instructions.
- Sanitization: No specific sanitization or escaping of project file content is mentioned.
- [CREDENTIALS_UNSAFE]: The
templates/internal.mdfile contains placeholders for sensitive information likeAPI_KEYandDATABASE_URL. These are provided solely as examples for documentation purposes and do not contain real secrets or instructions to leak them. - [EXTERNAL_DOWNLOADS]: The documentation and reference files (e.g.,
references/art-of-readme.md,references/standard-readme-spec.md) contain links to external GitHub repositories and documentation sites (such ashackergrrl/art-of-readme,makeareadme.com, andstandard-readme). These are well-known community resources used for informational reference.
Audit Metadata