blockdoc
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from user-provided files, creating an attack surface where malicious instructions could be embedded. 1. Ingestion points: Content is read from files in split_file, build, and check functions. 2. Boundary markers: No delimiters or ignore-instructions markers are present. 3. Capability inventory: The script has file-writing capabilities via open() in split_file and build functions. 4. Sanitization: Tag-balance validation is performed, but no filtering for prompt injection patterns is present.
- [COMMAND_EXECUTION]: The script scripts/blockdoc.py accepts command-line arguments to perform local file and directory operations, such as creating parts directories and writing assembled files. These operations are confined to the local filesystem and do not execute external shell commands.
Audit Metadata