skills/anntnzrb/agents/emacs/Gen Agent Trust Hub

emacs

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/emacsctl.py utilizes subprocess.run to execute the emacsclient binary for runtime communication with the Emacs server. This is a standard and necessary function for the skill's operation.\n- [EXTERNAL_DOWNLOADS]: Documentation in SKILL.md suggests using nix shell to obtain the info documentation system in environments where it is unavailable. This leverages the well-known Nix package manager to provide legitimate system utilities.\n- [PROMPT_INJECTION]: The skill facilitates reading state and content directly from a running Emacs instance, creating a surface for indirect prompt injection attacks.\n
  • Ingestion points: Untrusted data enters the agent context via scripts/emacsctl.py (specifically cmd_buffer and cmd_eval functions) and query patterns defined in references/common-queries.md.\n
  • Boundary markers: The skill does not implement delimiters or explicit 'ignore embedded instructions' warnings when retrieving data from the Emacs runtime.\n
  • Capability inventory: The skill can execute arbitrary Elisp code (which can spawn shell commands) and perform file system writes via standard agent capabilities as described in the workflow instructions.\n
  • Sanitization: Content fetched from Emacs buffers and variables is not sanitized or validated before being presented to the agent for processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 10:29 PM
Security Audit — agent-trust-hub — emacs