agentsmd-claudemd-generator

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from existing repository documentation to generate project-specific guidelines, creating a surface for potential injection.
  • Ingestion points: Documentation files such as README.md and CONTRIBUTING.md are analyzed during Phase 1 to provide context for the generated instructions.
  • Boundary markers: The skill lacks explicit instructions or delimiters that would direct the agent to ignore malicious instructions embedded within the source files being analyzed.
  • Capability inventory: The skill has Write and Edit permissions, which it uses to create the final AGENTS.md and CLAUDE.md guidelines.
  • Sanitization: There is no evidence of filtering or validation performed on the ingested content before it is incorporated into the output files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 04:57 PM
Security Audit — agent-trust-hub — agentsmd-claudemd-generator