skills/thorwhalen/skill/skill-docs/Gen Agent Trust Hub

skill-docs

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill suggests or uses standard shell commands such as 'ls' to locate skill files and 'python -c' to identify the installation path of the package. These operations are limited to local project discovery and are typical for documentation automation tools.
  • [PROMPT_INJECTION]: The skill processes untrusted data from external skill files to generate documentation. While this creates a surface for indirect prompt injection, it is considered safe in this context as the primary purpose of the skill is to reflect project content. * Ingestion points: Skill files located in '.claude/skills/' or '{pkg_name}/data/skills/'. * Boundary markers: Not present in the templates. * Capability inventory: File discovery and text generation for README files. * Sanitization: None detected for the content extracted from skill descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 06:02 AM
Security Audit — agent-trust-hub — skill-docs