gen-docs
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The instructions require the agent to execute a local maintenance script using the command
node docs/scripts/sync-changelog.mjs. This involves executing code within the workspace environment. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to parse and act upon data from
git commitmessages andstaged changes. Because these sources can be influenced by external contributors, they represent an attack surface where hidden instructions could be embedded to manipulate the agent's documentation generation process.
Audit Metadata