Document Skills

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes workflows for generating files from raw text or data, which presents an attack surface where untrusted input could be processed during document assembly.
  • Ingestion points: Raw text or data prompts as described in SKILL.md.
  • Boundary markers: None mentioned in the architectural guidance.
  • Capability inventory: The skill suggests using document generation libraries (Puppeteer, python-docx, etc.) but provides no implementation code or active tools.
  • Sanitization: The guidance does not explicitly specify sanitization or validation of input data before it is mapped to document templates.
  • [NO_CODE]: The skill consists entirely of instructional markdown content. No executable scripts, binaries, or active logic are included in the skill package.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:26 PM
Security Audit — agent-trust-hub — Document Skills