Document Skills
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes workflows for generating files from raw text or data, which presents an attack surface where untrusted input could be processed during document assembly.
- Ingestion points: Raw text or data prompts as described in SKILL.md.
- Boundary markers: None mentioned in the architectural guidance.
- Capability inventory: The skill suggests using document generation libraries (Puppeteer, python-docx, etc.) but provides no implementation code or active tools.
- Sanitization: The guidance does not explicitly specify sanitization or validation of input data before it is mapped to document templates.
- [NO_CODE]: The skill consists entirely of instructional markdown content. No executable scripts, binaries, or active logic are included in the skill package.
Audit Metadata