build-project-docs
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (the user's source code and Git history) to generate documentation, creating a vulnerability surface where malicious instructions embedded in the code could influence agent behavior.
- Ingestion points: The skill reads all project source files, build configurations (pom.xml, package.json), and Git commit history across multiple phases (Phase 1: Explore, Phase 4: Foundation, Phase 5: Business, Phase 7: Changelog).
- Boundary markers: The instructions lack explicit delimiters or warnings to the agent to disregard natural language instructions found within the source code being analyzed.
- Capability inventory: The agent is granted capabilities to
Read,Write,Editfiles, and executeBashcommands includinggit,find,wc,head, andls. - Sanitization: There is no mention of sanitizing or escaping the content read from the codebase before it is used to generate documentation prompts or output.
- [COMMAND_EXECUTION]: The skill relies on shell commands to inspect the filesystem and project history. While the
allowed-toolsfield restrictsBashto a specific set of tools (git,find,wc,head,ls), these tools are used dynamically to process the local environment. - Evidence:
phase-7-changelog.mdinstructs the use ofgit logandgit showto extract history, andSKILL.mdspecifies usingfind -newerto detect changes for incremental updates.
Audit Metadata