qa-docs-coverage

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The docs_freshness_report.py script executes git commands using subprocess.check_output to query commit timestamps for freshness analysis. This is implemented using argument lists to avoid shell-related vulnerabilities.\n- [EXTERNAL_DOWNLOADS]: The check_external_links.py script performs HTTP/HTTPS network requests using urllib.request to verify the availability of external documentation links found within the repository.\n- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing markdown content and metadata from the repository it audits. 1. Ingestion points: Markdown files and frontmatter metadata parsed by audit scripts. 2. Boundary markers: Absent. 3. Capability inventory: Git subprocess calls and network URL probing. 4. Sanitization: Regex for link extraction and YAML parsing for frontmatter.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — qa-docs-coverage