nia-docs

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Python script (scripts/mcp/nia_docs.py) using uv run and shell commands to perform documentation searches.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a vulnerability surface where untrusted user input is ingested and passed directly into a shell execution environment.
  • Ingestion points: User-provided search queries, package names, and regex patterns passed to the --query, --search, and --grep flags in SKILL.md.
  • Boundary markers: The usage examples do not include delimiters or specific instructions to the agent to sanitize or ignore embedded instructions within the user-provided query strings.
  • Capability inventory: The skill utilizes shell execution (Bash) and file reading capabilities.
  • Sanitization: There is no explicit sanitization or escaping of user-provided strings before they are interpolated into the shell command, which could lead to command injection if a user provides a malicious payload.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — nia-docs