01-user-manual
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows a well-defined workflow to generate documentation according to ISO 26514 standards. It operates locally by reading and writing files within the project directory.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from local files like
features.mdanduser_stories.md. While this creates an attack surface for indirect prompt injection, it is assessed as safe because the skill lacks capabilities for network communication, privilege escalation, or arbitrary code execution, and the source files are expected to be part of the user's own project repository.
Audit Metadata