build-project-docs

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (the user's source code and Git history) to generate documentation, creating a vulnerability surface where malicious instructions embedded in the code could influence agent behavior.
  • Ingestion points: The skill reads all project source files, build configurations (pom.xml, package.json), and Git commit history across multiple phases (Phase 1: Explore, Phase 4: Foundation, Phase 5: Business, Phase 7: Changelog).
  • Boundary markers: The instructions lack explicit delimiters or warnings to the agent to disregard natural language instructions found within the source code being analyzed.
  • Capability inventory: The agent is granted capabilities to Read, Write, Edit files, and execute Bash commands including git, find, wc, head, and ls.
  • Sanitization: There is no mention of sanitizing or escaping the content read from the codebase before it is used to generate documentation prompts or output.
  • [COMMAND_EXECUTION]: The skill relies on shell commands to inspect the filesystem and project history. While the allowed-tools field restricts Bash to a specific set of tools (git, find, wc, head, ls), these tools are used dynamically to process the local environment.
  • Evidence: phase-7-changelog.md instructs the use of git log and git show to extract history, and SKILL.md specifies using find -newer to detect changes for incremental updates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:00 AM
Security Audit — agent-trust-hub — build-project-docs