skills/angusfretwell/skills/show-me/Gen Agent Trust Hub

show-me

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes potentially untrusted external data such as pull requests, issues, and branch diffs to determine the subject and scope of the documentation. An attacker could embed malicious instructions in these sources to influence the agent's behavior. \n
  • Ingestion points: Pull request links, issue links, branch diffs, and project documentation files referenced during the subject search. \n
  • Boundary markers: The instructions do not specify any delimiters or safety headers to distinguish between user data and system instructions. \n
  • Capability inventory: The agent is authorized to launch applications, execute project scripts, and write files to the local system. \n
  • Sanitization: There is no mention of filtering, escaping, or validating the external content before it is incorporated into the agent's workflow.
  • [COMMAND_EXECUTION]: To generate visual captures, the skill directs the agent to launch the application and drive its UI using scripts or documentation found within the project. This requires the execution of arbitrary local commands determined by the project's content. \n
  • Evidence: The instruction states: 'How to launch and drive is project knowledge: a project skill that covers it first, else the project's own docs and scripts.' (SKILL.md)
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 01:31 AM
Security Audit — agent-trust-hub — show-me