storage-permissions

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled shell script scripts/check-storage.sh to collect diagnostic information about the Termux environment, including home directory writability, availability of storage symlinks, and disk space status.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied file paths and error messages to provide troubleshooting guidance.
  • Ingestion points: User-provided failing paths are captured as preconditions in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters for separating user-supplied paths from instructional prompts.
  • Capability: The skill has the ability to execute a shell script for environment discovery and provides natural language recommendations based on the output.
  • Sanitization: The diagnostic script performs read-only checks (existence, writability, and symlink targets) and does not parse or execute the content of the user-provided files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 09:05 AM
Security Audit — agent-trust-hub — storage-permissions