kmp-project-docs-maintainer
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Several maintenance scripts (
heal_project.py,generate_skills_lock.py,new_task.py) utilizesubprocess.runto perform routine project tasks, such as executing local Python maintenance scripts and interacting withgit. These operations are scoped to the project directory and are standard for developer productivity tools. - [EXTERNAL_DOWNLOADS]: The
check_skills_lock.pyscript queries the GitHub API (api.github.com) to check for the latest releases of thekmp-agent-skillsrepository, facilitating project updates. Additionally,SKILL.mdcontains a recommendation for the third-party toolconorbronsdon/avoid-ai-writingfor auditing prose. - [PERSISTENCE]: The
heal_project.pyscript manages the installation and synchronization of apre-commitgit hook within the project's.git/hooks/directory. This is a common automation practice to ensure code and documentation quality checks are run before commits. - [INDIRECT_PROMPT_INJECTION]: The skill implements a documentation self-healing engine that reads and summarizes markdown files (
.md) throughout the project. This ingestion of potentially untrusted project content creates a surface for indirect prompt injection. - Ingestion points:
heal_docs.pyrecursively reads all markdown files in thedocs/directory to generate sitemaps and task indexes. - Boundary markers: The skill does not employ specific delimiters or "ignore instructions" tags when processing file content for document summaries.
- Capability inventory: The skill possesses capabilities for filesystem writes, script permission modification, and shell command execution via
subprocess.run. - Sanitization: Basic string escaping is performed for markdown table formatting, but the skill does not implement semantic validation or safety filtering for the documentation content it processes.
Audit Metadata