glimmer-delegation

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the Ollama installation script from the official ollama.com domain.
  • [REMOTE_CODE_EXECUTION]: Installs the Ollama tool by piping the official installation script to the shell as part of the setup instructions.
  • [COMMAND_EXECUTION]: Uses the ollama CLI and a local Python script to delegate tasks to the local model.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external file content and user prompts by inlining them into the model context, which represents a potential injection surface.
  • Ingestion points: User prompts and file contents are ingested via CLI arguments and stdin (SKILL.md).
  • Boundary markers: None mentioned; content is inlined directly into the prompt.
  • Capability inventory: Executes shell commands via the ollama binary.
  • Sanitization: No specific sanitization or filtering is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:05 AM
Security Audit — agent-trust-hub — glimmer-delegation