indexion-readme
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process external data sources such as project configuration (
doc.json), static markdown files (docs/*.md), and source code doc comments (///) to generate and assemble README files. This ingestion of untrusted data could potentially allow embedded malicious instructions to influence the agent's behavior during the planning or assembly steps. - Ingestion points: Reads
doc.json, markdown files indocs/, and source code directories for API extraction. - Boundary markers: The instructions do not define explicit delimiters or 'ignore embedded instructions' warnings for the data being processed.
- Capability inventory: The skill uses the
indexionCLI to write files to the local file system (README.md, per-package READMEs). - Sanitization: No sanitization or validation of the ingested content is described before it is processed by the agent or the assembly tool.
Audit Metadata