readme-generator

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze project features and code to generate documentation. This process creates an attack surface where malicious instructions embedded in project files could potentially override agent behavior during analysis.
  • Ingestion points: Project source code, configuration files, and existing documentation are read during the 'Analyze project' step in SKILL.md.
  • Boundary markers: Instructions do not define specific delimiters or warnings to prevent the agent from following instructions found within the analyzed project files.
  • Capability inventory: The agent requires file system read access to analyze the project and file system write access to generate documentation files.
  • Sanitization: No explicit instructions are provided to sanitize content extracted from project files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:31 AM
Security Audit — agent-trust-hub — readme-generator