docs-architect

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it is designed to ingest and process untrusted data from external codebases without defining security boundaries.
  • Ingestion points: The agent is instructed to analyze codebase structures, dependencies, and implementation details from existing repositories (SKILL.md).
  • Boundary markers: The instructions lack explicit delimiters or guidance to ignore potentially malicious instructions embedded in code comments or documentation strings within the analyzed files.
  • Capability inventory: The skill possesses the capability to read local file contents and generate large-scale documentation based on that content (SKILL.md).
  • Sanitization: There are no specified mechanisms for filtering or sanitizing content extracted from the target codebase before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 09:22 AM
Security Audit — agent-trust-hub — docs-architect