documentation-generation-doc-generate

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from external sources, specifically code, configurations, and comments within a repository. This creates a surface where malicious instructions embedded in the analyzed codebase could potentially influence the agent's behavior. The skill includes safety instructions to avoid exposing secrets but lacks explicit boundary delimiters for the ingested content.
  • [EXTERNAL_DOWNLOADS]: The implementation playbook references external assets and tools from well-known services. Specifically, it includes templates for fetching Swagger UI components from jsdelivr.net and utilizes the peaceiris/actions-gh-pages action for GitHub-based deployments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:05 PM
Security Audit — agent-trust-hub — documentation-generation-doc-generate