shiki-code-blocks
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes a command to fetch a markdown file from an external server.
- Evidence:
curl https://fullstackrecipes.com/recipes/shiki-code-blocks.mdinSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could contain malicious instructions.
- Ingestion points: Content downloaded from
https://fullstackrecipes.com/recipes/shiki-code-blocks.mdenters the agent's context. - Boundary markers: Absent; there are no delimiters or instructions to treat the external content as untrusted data.
- Capability inventory: The agent possessing this skill typically has access to tools (e.g., shell or file system) that could be targeted by instructions embedded in the external content.
- Sanitization: Absent; the skill does not perform any validation or filtering on the retrieved content.
Audit Metadata