init
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for the legitimate purpose of generating repository documentation and does not contain any malicious code, obfuscation, or unauthorized access patterns.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it processes untrusted content from the local repository to generate its output. Ingestion points: Reads repository structure, package.json, Makefile, pyproject.toml, .cursorrules, .github/copilot-instructions.md, README.md, AGENTS.md, CLAUDE.md, and git commit history. Boundary markers: No explicit boundary markers or 'ignore' instructions are used for the ingested content. Capability inventory: The skill has the capability to write to the file system to create or update the AGENTS.md file. Sanitization: No explicit validation or sanitization of the content extracted from the repository files is described. However, given the primary purpose of the skill is documentation generation, this is considered a functional characteristic rather than a high-risk vulnerability.
Audit Metadata