glimmer-delegation
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the Ollama installation script from the official ollama.com domain.
- [REMOTE_CODE_EXECUTION]: Installs the Ollama tool by piping the official installation script to the shell as part of the setup instructions.
- [COMMAND_EXECUTION]: Uses the ollama CLI and a local Python script to delegate tasks to the local model.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external file content and user prompts by inlining them into the model context, which represents a potential injection surface.
- Ingestion points: User prompts and file contents are ingested via CLI arguments and stdin (SKILL.md).
- Boundary markers: None mentioned; content is inlined directly into the prompt.
- Capability inventory: Executes shell commands via the ollama binary.
- Sanitization: No specific sanitization or filtering is described.
Audit Metadata