api-documenter

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface where untrusted data from external research (via tools like exa search and deep research) could contain malicious instructions. Because the agent is granted powerful capabilities including Bash, Read, Write, and Edit with no explicit sanitization or validation steps for external content, an attacker could potentially influence the agent's actions through malicious web content or third-party documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 10:15 AM
Security Audit — agent-trust-hub — api-documenter