write-readme
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is strictly instructional and focused on text generation for documentation purposes. It contains no executable scripts, shell commands, or network activity.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external inputs such as package APIs and other README files. This creates a surface for indirect prompt injection. However, since the skill only outputs text and does not possess capabilities for code execution or system modification, the risk is negligible and restricted to the content of the generated documentation. Evidence: 1. Ingestion points: Reads package API and sibling package READMEs (SKILL.md); 2. Boundary markers: Absent; 3. Capability inventory: Text generation only; 4. Sanitization: Absent.
Audit Metadata