Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThe skill automates documentation drafting by reading local specification files and interacting with the vendor's GitHub repositories. It presents a potential surface for indirect prompt injection because it processes content from engineer-provided files to generate pull requests, though it includes manual confirmation steps as a safeguard.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · 2 issues