agents-md-generator

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes local repository files which could contain untrusted content that influences the generated documentation.
  • Ingestion points: The skill reads package.json, README.md, Makefile, and existing AGENTS.md files during the discovery and module detection phases (SKILL.md).
  • Boundary markers: Documentation is generated using predefined templates (references/AGENTS_TEMPLATE_ROOT.md, references/AGENTS_TEMPLATE_MODULE.md) with explicit instructions to replace placeholders.
  • Capability inventory: The skill utilizes filesystem read/write access to locate project markers and update documentation files.
  • Sanitization: The agent is explicitly instructed to avoid inventing commands, to verify commands against authoritative project files, and to preserve all security and deployment warnings from existing documentation (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:57 PM
Security Audit — agent-trust-hub — agents-md-generator