design
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a documentation generation tool with no malicious code, network access, or sensitive data exposure detected. It includes a proactive security review section in its design template.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests project source code and linked materials to inform the design process. This constitutes a surface where embedded instructions in those files could theoretically influence the agent's output, though the risk is limited to the content of the generated markdown document.
- Ingestion points: Repository instructions, code, and linked material (SKILL.md, Step 1).
- Boundary markers: None specified.
- Capability inventory: File writing to docs/ (SKILL.md, Step 4).
- Sanitization: None specified.
Audit Metadata