skills/moonshotai/kimi-cli/gen-docs/Gen Agent Trust Hub

gen-docs

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The instructions require the agent to execute a local maintenance script using the command node docs/scripts/sync-changelog.mjs. This involves executing code within the workspace environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to parse and act upon data from git commit messages and staged changes. Because these sources can be influenced by external contributors, they represent an attack surface where hidden instructions could be embedded to manipulate the agent's documentation generation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:10 AM
Security Audit — agent-trust-hub — gen-docs