emacs
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/emacsctl.pyutilizessubprocess.runto execute theemacsclientbinary for runtime communication with the Emacs server. This is a standard and necessary function for the skill's operation.\n- [EXTERNAL_DOWNLOADS]: Documentation inSKILL.mdsuggests usingnix shellto obtain theinfodocumentation system in environments where it is unavailable. This leverages the well-known Nix package manager to provide legitimate system utilities.\n- [PROMPT_INJECTION]: The skill facilitates reading state and content directly from a running Emacs instance, creating a surface for indirect prompt injection attacks.\n - Ingestion points: Untrusted data enters the agent context via
scripts/emacsctl.py(specificallycmd_bufferandcmd_evalfunctions) and query patterns defined inreferences/common-queries.md.\n - Boundary markers: The skill does not implement delimiters or explicit 'ignore embedded instructions' warnings when retrieving data from the Emacs runtime.\n
- Capability inventory: The skill can execute arbitrary Elisp code (which can spawn shell commands) and perform file system writes via standard agent capabilities as described in the workflow instructions.\n
- Sanitization: Content fetched from Emacs buffers and variables is not sanitized or validated before being presented to the agent for processing.
Audit Metadata