gleam
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow where the agent ingests data from external sources, creating a potential attack surface.
- Ingestion points: The
reference.mdfile directs the agent to query thecontext7 docstool and the GitHub CLI (gh) for information from various repositories, includinggleam-lang/stdlib,rawhat/mist, andschurhammer/gleamy_structures. - Boundary markers: There are no explicit instructions or delimiters defined to help the agent distinguish between its own system instructions and instructions that might be embedded within the external documentation or code it retrieves.
- Capability inventory: The skill provides the agent with the ability to execute code via
gleam runandgleam test, and to interact with the GitHub API via theghCLI. This creates a path where instructions found in external data could influence local code execution. - Sanitization: The skill does not include instructions for sanitizing or validating the content retrieved from these external libraries before processing it.
Audit Metadata