doc-research
Pass
Audited by Gen Agent Trust Hub on Mar 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local binaries
c7.tsandweb2md.tslocated in~/.local/bin/to search documentation and render HTML content.\n- [EXTERNAL_DOWNLOADS]: Theweb2md.tstool retrieves content from remote URLs, andc7.tsfetches documentation from external library registries.\n- [PROMPT_INJECTION]: The skill handles untrusted external data which presents an indirect prompt injection surface.\n - Ingestion points: External web content from URLs provided to
web2md.tsand library documentation retrieved viac7.ts(SKILL.md, references/web2md.md, references/c7-cli.md).\n - Boundary markers: The 'Content Trust' section in SKILL.md provides explicit instructions to the agent to treat fetched content as untrusted.\n
- Capability inventory: The agent can execute CLI tools and read their output into its context (SKILL.md).\n
- Sanitization: Guidelines instruct the agent to verify information and avoid executing code snippets from the web without review (SKILL.md).
Audit Metadata