setup
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local TypeScript scripts using
bun runwithin the${CLAUDE_PLUGIN_ROOT}directory. These commands (config.ts detect,show,get,set) are used to manage environment variables and local configuration files (~/.config/gemskills/config.json) associated with the agent's functionality. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user input through an interactive flow or direct CLI calls to set provider defaults.
- Ingestion points: User-provided strings for provider names (e.g., 'openai', 'xai') and task types (e.g., 'image', 'video') in SKILL.md.
- Boundary markers: None identified.
- Capability inventory: Execution of internal CLI tools via
bun runand file writing to local configuration paths. - Sanitization: None explicitly described in the instructions, though inputs are restricted to specific provider keywords.
- [CREDENTIALS_UNSAFE]: The skill references standard API key environment variables (GEMINI_API_KEY, OPENAI_API_KEY, XAI_API_KEY) to detect provider availability. It follows security best practices by instructing users to set these in their own environment rather than providing hardcoded secrets.
Audit Metadata