docs-writing

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions create a vulnerability surface for indirect prompt injection by requiring the agent to ingest and act upon untrusted content within user-provided documentation. \n
  • Ingestion points: Technical documentation files (Markdown) provided by the user for auditing or improvement. \n
  • Boundary markers: The skill lacks explicit boundary markers or instructions to ignore embedded commands within the processed documentation fences. \n
  • Capability inventory: The agent is instructed to use its command execution capabilities to verify examples. \n
  • Sanitization: No sanitization or safety checks are defined for the code blocks before execution. \n- [COMMAND_EXECUTION]: The Writing Workflow in SKILL.md (Step 5) explicitly mandates the agent to 'run every example' to verify documentation correctness. This instruction potentially allows for the execution of arbitrary shell commands or code if they are present in the documentation file being reviewed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 09:34 PM
Security Audit — agent-trust-hub — docs-writing