runbook-generator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates locally by reading the project codebase, configurations, and scripts via static analysis (
Glob,Grep,Read) to gather operational context. - [SAFE]: The execution workflow builds documentation strictly on what it discovers within the codebase, using clear templates and avoiding external command executions or unvetted remote connections.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted codebase content (READMEs, configuration values, external documentation links) that could theoretically contain indirect injection vectors. However, the risk is mitigated because the ingested content is mapped statically to predefined textual fields, checklist headers, and structural sections without executing or dynamically expanding the contents inside high-privilege blocks. (Mandatory Tier: Ingestion point in SKILL.md reads workspace config files; Boundary markers absent; Capability inventory limited to filesystem read and text generation; Sanitization absent, but instructions guide writing rather than execution).
Audit Metadata