polish-technical-docs
Pass
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to "Directly edit the original file (Read + Edit/Write), do not paste full file in reply" and "return optimized Markdown, not adding preambles, explanations or change summaries." These instructions promote autonomous modification of files and concealment of the agent's intermediate reasoning or status updates from the user. While this reduces user oversight, it is a functional requirement for the skill's intended use case of efficient document editing and does not attempt to bypass safety filters or override core agent behavior.
- [DATA_EXPOSURE]: The skill operates on user-provided technical drafts and does not contain hardcoded credentials, access sensitive system paths, or perform unauthorized network operations.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data (technical documents) and possesses the capability to write modifications back to the file system. It lacks specific boundary markers to distinguish between the document content and instructions, creating a surface for potential injection if a document contains malicious commands.
- Ingestion points: User-provided text or file paths (SKILL.md)
- Boundary markers: Absent
- Capability inventory: File read and write operations (SKILL.md)
- Sanitization: Absent
Audit Metadata