absolute-docs

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill's workflow for writing and auditing documentation involves reading the user's codebase and existing documents, which creates an attack surface for indirect prompt injection if those files contain malicious instructions.
  • Ingestion points: SKILL.md (Step 1
  • Recon: "Read existing docs", "Read the code being documented", "Check project metadata").
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded prompts in the ingested data.
  • Capability inventory: The skill relies on the agent's native tools for file reading and writing across its WRITE, IMPROVE, and AUDIT modes.
  • Sanitization: No explicit content filtering or validation of the codebase data is specified.
  • [SAFE]: No malicious patterns such as exfiltration, persistence, or unauthorized command execution were detected. The skill uses local reference files to ensure documentation accuracy and adheres to established standards.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 03:07 AM
Security Audit — agent-trust-hub — absolute-docs