readme-generator

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a standard documentation workflow involving research and project analysis. All activities are scoped to documentation generation.
  • [EXTERNAL_DOWNLOADS]: The skill uses the Exa web search tool to retrieve README best practices. This is a legitimate use of a platform tool for research purposes.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project data (e.g., package.json, CLAUDE.md) and external search results. While this creates an ingestion surface for potential instructions hidden in project files, the impact is limited to the content of the generated README file.
  • Ingestion points: project configuration files (package.json, pyproject.toml, Cargo.toml), CLAUDE.md, and search results from the Exa tool.
  • Boundary markers: None explicitly specified for the generation phase.
  • Capability inventory: File system read (project files), web search (Exa), and file system write (README.md).
  • Sanitization: No specific sanitization or filtering of input content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 08:56 PM
Security Audit — agent-trust-hub — readme-generator