soia-dev-doc-sync

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted content from external repositories which could be leveraged to influence agent behavior through indirect prompt injection. * Ingestion points: Target repository files including source code, documentation, and metadata. * Boundary markers: The skill lacks explicit instructions to treat repository content as untrusted data using delimiters or safety warnings. * Capability inventory: Executes shell commands for lint, tests, and generators; performs file system operations (write/repair). * Sanitization: Guidelines specify desensitization of findings before generating reports.
  • [COMMAND_EXECUTION]: The skill is designed to execute project-specific utility commands, such as link checkers, linters, and test suites, which are defined within the repository being audited.
  • [EXTERNAL_DOWNLOADS]: The documentation describes the installation of skill components from the vendor's official GitHub repository (soia-team/soia-open-skills).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 07:59 AM
Security Audit — agent-trust-hub — soia-dev-doc-sync