doc-spec
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were detected. The skill is purely instructional, guiding the agent to generate YAML-formatted documentation based on internal project files.
- [INDIRECT_PROMPT_INJECTION]: The skill involves reading and summarizing content from upstream artifacts (ADR, BDD, and EARS files). While this represents a data ingestion surface where external instructions could theoretically be placed, the skill possesses no dangerous capabilities—such as network access, system modification, or arbitrary code execution—that would allow for exploitation of such an injection. The risk is assessed as safe within the context of its intended use.
- [COMMAND_EXECUTION]: The skill uses a simple directory listing command (
ls) to check for the existence of files and prevent ID collisions. This is a standard, low-privilege filesystem operation necessary for the skill's functionality.
Audit Metadata