review-docs
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external documentation content and configuration files.
- Ingestion points: The skill reads Markdown files (
.md), navigation files (.navigation.yml), and project configurations (package.json,nuxt.config.ts) as specified in theWorkflow OverviewandStep 1: Detect Project Typesections ofSKILL.md. - Boundary markers: The skill instructions do not define specific delimiters or explicit safety warnings for the agent to treat analyzed content as untrusted data, potentially allowing embedded instructions in documentation to influence agent behavior.
- Capability inventory: The skill generates a comprehensive report and offers to automatically fix identified technical issues, which involves file-writing operations.
- Sanitization: The instructions do not include requirements for sanitizing, escaping, or validating the content of the documentation before the agent processes it for quality and technical checks.
Audit Metadata