doc-maintenance
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data from git commit messages and file contents to perform its audit logic, creating a surface for potential prompt injection.
- Ingestion points: The skill reads commit logs via
git logand the full text ofREADME.md,doc/SPEC.md, anddoc/PRODUCT.md. - Boundary markers: There are no explicit delimiters or specific instructions for the agent to ignore potentially malicious content within these data sources.
- Capability inventory: The skill has the capability to read project files, write to the filesystem (cursor files and branch edits), execute shell commands, and interact with the GitHub API to create Pull Requests.
- Sanitization: No explicit filtering or sanitization of the git history or documentation content is performed prior to analysis.
- [COMMAND_EXECUTION]: The workflow relies on standard shell commands (
git,gh,bash,cat) to automate repository management tasks. These commands are used as intended for document auditing and branch creation. - [DATA_EXFILTRATION]: The skill performs network operations to push document updates to the remote repository (
git push) and open Pull Requests (gh pr create). These operations target the project's own infrastructure and are consistent with the skill's primary function of maintaining documentation accuracy.
Audit Metadata