docsmith-development
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is configured to ingest and process Markdown content from local sources and remote repositories, creating a surface for indirect instructions.
- Ingestion points: Markdown files in the specified source directory and remote Git repositories defined in docsmith.sources.php (SKILL.md).
- Boundary markers: No explicit markers are defined to isolate untrusted content from the agent's instructions.
- Capability inventory: Includes file system writes to the output directory and network operations for repository syncing (SKILL.md).
- Sanitization: Content is rendered via CommonMarkRenderer, but no specific mechanisms are described to filter or sanitize malicious natural language prompts.
- [COMMAND_EXECUTION]: The instructions require the agent to execute shell commands using tools like composer, php, npm, and npx to initialize the project and build the site.
- [EXTERNAL_DOWNLOADS]: The skill fetches external code and content, including the mrpunyapal/docsmith vendor library and Microsoft's playwright package for generating Open Graph images.
Audit Metadata