documentation
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes project code to generate documentation, representing a potential surface for indirect prompt instructions. \n
- Ingestion points: Reads code files and existing comments to generate READMEs, PHPDoc, and API documentation as described in SKILL.md and references/phpdoc.md. \n
- Boundary markers: None explicitly defined in the templates to separate source code from generated documentation blocks. \n
- Capability inventory: The skill provides instructions for shell-based tool usage (e.g., git, composer, pnpm) but does not include tool definitions for automated execution. \n
- Sanitization: No sanitization or validation logic is specified for processing external code content. \n- [EXTERNAL_DOWNLOADS]: The skill includes links to standard developer resources and tools in its documentation templates. \n
- Evidence: Links to GitHub, badge services (shields.io), and documentation standards (Semantic Versioning, Keep a Changelog) in references/readme.md. \n
- Scanner Alert: A link to https://www.shadcn-vue.com was flagged by scanners. This domain is the official site for a popular Vue port of the shadcn/ui library and is appropriately included in the acknowledgments section of a project template. The reference is documented neutrally as it targets a well-known community project.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata