01-user-manual

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows a well-defined workflow to generate documentation according to ISO 26514 standards. It operates locally by reading and writing files within the project directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from local files like features.md and user_stories.md. While this creates an attack surface for indirect prompt injection, it is assessed as safe because the skill lacks capabilities for network communication, privilege escalation, or arbitrary code execution, and the source files are expected to be part of the user's own project repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 02:45 AM
Security Audit — agent-trust-hub — 01-user-manual