update-docs
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the local codebase, including git diffs, changed file lists, and documentation content, which are interpolated directly into prompts for sub-agents (e.g., '{GIT_DIFF_SUMMARY}', '{CHANGED_FILES_LIST}', '{DOCUMENTATION_TASKS_LIST}'). This creates a surface where malicious instructions embedded in code comments or documentation could theoretically influence the behavior of the documentation and review agents.
- Ingestion points: Reads uncommitted changes, git history, configuration files (package.json, pyproject.toml), and existing documentation files (.md, .rst).
- Boundary markers: The templates for sub-agents (Analysis, Tech Writer, Quality Review) do not use explicit delimiters or "ignore instructions" warnings to wrap the interpolated codebase content.
- Capability inventory: The skill can execute shell commands (git, find, grep), write/modify local files, and orchestrate additional AI agents.
- Sanitization: No sanitization, filtering, or escaping is performed on the ingested code or diff content before it is processed by the agents.
- [COMMAND_EXECUTION]: The skill uses standard shell commands including 'find', 'grep', 'git status', and 'git show' to inventory project documentation and identify changed files. These operations are restricted to the local project environment and serve the primary purpose of the skill.
Audit Metadata