ntm
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is built to execute arbitrary caller-supplied shell commands within persistent terminal panes via the
ntmCLI tool (e.g.,ntm --robot-capabilities,ntm --robot-snapshot). - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of shell commands received via the
pane-command-requestmechanism. While the skill defines strict operational boundaries, the processing of external commands creates an attack surface. - Ingestion points: The skill consumes
pane-command-requestas specified in the YAML frontmatter. - Boundary markers: Detailed instructions in the 'Boundary' and 'One-shot dispatch' sections provide constraints, such as 'Dispatch each caller-supplied command once' and 'Never start or probe NTM merely because it is installed'.
- Capability inventory: Shell command execution and monitoring of process transcripts and robot state.
- Sanitization: The skill emphasizes returning 'factual session, pane, command, and observation results' rather than interpreting or validating the commands themselves.
Audit Metadata