skills/aeondave/malskill/exiftool/Gen Agent Trust Hub

exiftool

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for using the exiftool utility to read, write, and manipulate file metadata through shell commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of external, untrusted file metadata which is then introduced into the agent's conversation context.
  • Ingestion points: External files (images, PDFs, videos) read by the agent using exiftool commands like exiftool file.jpg.
  • Boundary markers: Absent; there are no instructions to use delimiters or ignore instructions found within the extracted metadata.
  • Capability inventory: Shell access for file reading and writing across various formats.
  • Sanitization: Absent; metadata content is not sanitized before being presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — exiftool