docsmith-development

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is configured to ingest and process Markdown content from local sources and remote repositories, creating a surface for indirect instructions.
  • Ingestion points: Markdown files in the specified source directory and remote Git repositories defined in docsmith.sources.php (SKILL.md).
  • Boundary markers: No explicit markers are defined to isolate untrusted content from the agent's instructions.
  • Capability inventory: Includes file system writes to the output directory and network operations for repository syncing (SKILL.md).
  • Sanitization: Content is rendered via CommonMarkRenderer, but no specific mechanisms are described to filter or sanitize malicious natural language prompts.
  • [COMMAND_EXECUTION]: The instructions require the agent to execute shell commands using tools like composer, php, npm, and npx to initialize the project and build the site.
  • [EXTERNAL_DOWNLOADS]: The skill fetches external code and content, including the mrpunyapal/docsmith vendor library and Microsoft's playwright package for generating Open Graph images.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 06:02 PM
Security Audit — agent-trust-hub — docsmith-development