qa-docs-coverage
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
docs_freshness_report.pyscript executes git commands usingsubprocess.check_outputto query commit timestamps for freshness analysis. This is implemented using argument lists to avoid shell-related vulnerabilities.\n- [EXTERNAL_DOWNLOADS]: Thecheck_external_links.pyscript performs HTTP/HTTPS network requests usingurllib.requestto verify the availability of external documentation links found within the repository.\n- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing markdown content and metadata from the repository it audits. 1. Ingestion points: Markdown files and frontmatter metadata parsed by audit scripts. 2. Boundary markers: Absent. 3. Capability inventory: Git subprocess calls and network URL probing. 4. Sanitization: Regex for link extraction and YAML parsing for frontmatter.
Audit Metadata