wiki-onboarding
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes repository files (source code, build manifests such as
package.jsonorCargo.toml, and existing documentation) to generate its output. - Ingestion points: Files within the repository are accessed during the scan for build files and when tracing data flows or state from actual code.
- Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following instructions potentially embedded within the analyzed code (e.g., malicious comments designed to influence the guide's output).
- Capability inventory: The skill performs repository scanning and text generation, including the production of Mermaid diagrams and Markdown documentation.
- Sanitization: The instructions do not specify any validation or sanitization of content extracted from the files before it is interpolated into the generated guides.
Audit Metadata