writing-agents-md

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill analyzes untrusted repository content (e.g., README.md, package.json) to generate or review documentation, creating a surface for indirect prompt injection.\n
  • Ingestion points: The skill (Grounding workflow section) identifies repository files and manifests as data sources for agent inspection.\n
  • Boundary markers: The skill does not specify the use of delimiters or instructions to ignore embedded commands when reading files.\n
  • Capability inventory: The skill is restricted to text generation and review, with no direct execution or network capabilities.\n
  • Sanitization: The instructions explicitly forbid including secrets or security-bypassing commands in the output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 01:50 AM
Security Audit — agent-trust-hub — writing-agents-md