documentation-architect

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted data from existing software repositories to generate documentation that guides downstream agent actions.
  • Ingestion points: Section 16 (Existing Repository Analysis) instructs the agent to ingest source code, directory structures, package manifests, and environment configurations from the local project.
  • Boundary markers: The instructions do not define delimiters or explicit boundary markers to prevent the agent from following instructions hidden within the analyzed repository files.
  • Capability inventory: The skill's primary capability is text generation (markdown). While it lacks tools for network or command execution, its output is specifically designed to be executed by a downstream AI coding agent, creating a multi-step injection chain.
  • Sanitization: There are no instructions for sanitizing, escaping, or validating the content retrieved from the repository before it is incorporated into the documentation output.
  • [NO_CODE]: The skill consists exclusively of markdown instructions in the SKILL.md file. It does not include any executable scripts, binaries, or configuration files that could run on the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 01:10 PM
Security Audit — agent-trust-hub — documentation-architect