skill-docs
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill suggests or uses standard shell commands such as 'ls' to locate skill files and 'python -c' to identify the installation path of the package. These operations are limited to local project discovery and are typical for documentation automation tools.
- [PROMPT_INJECTION]: The skill processes untrusted data from external skill files to generate documentation. While this creates a surface for indirect prompt injection, it is considered safe in this context as the primary purpose of the skill is to reflect project content. * Ingestion points: Skill files located in '.claude/skills/' or '{pkg_name}/data/skills/'. * Boundary markers: Not present in the templates. * Capability inventory: File discovery and text generation for README files. * Sanitization: None detected for the content extracted from skill descriptions.
Audit Metadata