exiftool
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for using the
exiftoolutility to read, write, and manipulate file metadata through shell commands. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of external, untrusted file metadata which is then introduced into the agent's conversation context.
- Ingestion points: External files (images, PDFs, videos) read by the agent using
exiftoolcommands likeexiftool file.jpg. - Boundary markers: Absent; there are no instructions to use delimiters or ignore instructions found within the extracted metadata.
- Capability inventory: Shell access for file reading and writing across various formats.
- Sanitization: Absent; metadata content is not sanitized before being presented to the agent.
Audit Metadata