mcaf-documentation
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill's workflow involves reading and processing repository content, creating an indirect prompt injection surface where external data can influence agent actions.\n
- Ingestion points: Reads current documentation structure, code, policies, and workflows (SKILL.md).\n
- Boundary markers: Absent; there are no explicit delimiters or instructions provided to the agent to ignore embedded commands in the files it reads.\n
- Capability inventory: The skill can modify repository files, including documentation, code, configuration, tests, and CI artifacts (SKILL.md).\n
- Sanitization: Absent; the skill does not specify any validation or sanitization of the content ingested from the project files.\n- [SAFE]: No other malicious patterns, such as hardcoded credentials, unauthorized network communication, or persistence mechanisms, were detected in the skill files.
Audit Metadata