doc-research

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local binaries c7.ts and web2md.ts located in ~/.local/bin/ to search documentation and render HTML content.\n- [EXTERNAL_DOWNLOADS]: The web2md.ts tool retrieves content from remote URLs, and c7.ts fetches documentation from external library registries.\n- [PROMPT_INJECTION]: The skill handles untrusted external data which presents an indirect prompt injection surface.\n
  • Ingestion points: External web content from URLs provided to web2md.ts and library documentation retrieved via c7.ts (SKILL.md, references/web2md.md, references/c7-cli.md).\n
  • Boundary markers: The 'Content Trust' section in SKILL.md provides explicit instructions to the agent to treat fetched content as untrusted.\n
  • Capability inventory: The agent can execute CLI tools and read their output into its context (SKILL.md).\n
  • Sanitization: Guidelines instruct the agent to verify information and avoid executing code snippets from the web without review (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 02:45 PM
Security Audit — agent-trust-hub — doc-research