plaster-from-patch
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external code patches and Chromium source files to generate its output.
- Ingestion points: Reads patch content using
cat patches/<...>.patchand source code usinggit -C .. show HEAD:<path>. - Boundary markers: The instructions lack explicit delimiters or warnings to differentiate between instructions and the data being processed from the patches.
- Capability inventory: The skill has extensive file system access (
Read,Write,Edit) and the ability to execute shell commands viaBash(includingpython3,git, andpnpm). - Sanitization: No sanitization or validation is applied to the content extracted from the patches before it is used to author new configuration files.
- [EXTERNAL_DOWNLOADS]: The skill may attempt to install a dependency from the public Python Package Index (PyPI).
- Evidence: Step 3 includes an instruction to run
python3 -m pip install pyyamlif the library is missing. PyYAML is a well-known and standard library for YAML parsing. - [COMMAND_EXECUTION]: The skill executes local repository scripts and system commands to verify the generated configuration.
- Evidence: The skill runs
tools/cr/plaster.py applyto regenerate patches and uses various standard utilities such asgit,pnpm, anddifffor workflow management and verification.
Audit Metadata