yzr-sys-design-doc

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed purely for documentation generation. It uses predefined Markdown templates and does not include any instructions or tools for network communication, privileged system access, or execution of external code.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user-provided requirements and potentially from local code repositories specified by the user. While this constitutes an attack surface for indirect prompt injection, the skill lacks high-risk capabilities that would allow such an injection to be exploited for exfiltration or system compromise.\n
  • Ingestion points: User-provided natural language requirements and local code repository paths as described in SKILL.md.\n
  • Boundary markers: None explicitly defined in the templates to differentiate between instructions and processed data.\n
  • Capability inventory: Limited to reading local files and writing Markdown documentation to the local filesystem.\n
  • Sanitization: No specific input sanitization or filtering logic is present.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 04:01 AM
Security Audit — agent-trust-hub — yzr-sys-design-doc