docs-codebase
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and reorganize existing repository documentation, which constitutes an attack surface for indirect prompt injection. However, the skill mitigates this risk by establishing strict 'Markdown Creation Gates' and requiring the verification of all claims against the filesystem and repo reality. It also explicitly labels examples to distinguish them from exhaustive truths.
- [EXTERNAL_DOWNLOADS]: The skill references and recommends several established documentation tools (e.g., markdownlint-cli, Vale, cspell, markdown-link-check, MkDocs, Docusaurus) from official package registries (NPM, PyPI). It also maintains an extensive list of authoritative sources in
data/sources.json, all of which target reputable organizations and well-known services. - [COMMAND_EXECUTION]: Documentation files within the skill contain numerous shell command snippets and templates intended for local testing, CI/CD workflows, and repository maintenance (e.g., link validation, deployment scripts, and database migrations). These are presented as instructional examples and do not involve unauthorized or hidden execution.
- [DYNAMIC_EXECUTION]: The skill includes a mechanism for maintaining a project-specific 'learnings loop' via the
append_learning.pyscript. This is a standard design pattern for enhancing agent capabilities over time and is executed in a controlled, project-local context.
Audit Metadata