checkit
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local scripts and system tools using parameters derived from external user-provided artifacts.
- The instructions in
SKILL.mdspecify runningpython3 scripts/video_ingest.pywith a URL and an inferred query as arguments. - The skill provides a specific security directive to single-quote these arguments to prevent shell injection attacks from hostile URLs containing metacharacters.
- It also utilizes
gh apito traverse repository trees andffmpegfor video processing. - [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface by ingesting and analyzing content from arbitrary external sources, which could contain adversarial instructions.
- Ingestion points: The agent fetches data from GitHub repositories, research papers (arXiv), social media (X, Instagram), and video platforms (YouTube) as described in
SKILL.mdandreferences/checkit-lens.md. - Capability inventory: The skill has the ability to execute shell commands via local scripts and write to the agent's internal knowledge base.
- Boundary markers: The skill requires the agent to declare its inferred intent before processing, providing a level of context, but lacks explicit technical delimiters for the ingested content itself.
- Sanitization: Shell-level sanitization is performed via quoting, but the content remains subject to LLM interpretation.
- [EXTERNAL_DOWNLOADS]: The skill references and fetches data from numerous well-known external services for research purposes.
- Artifacts are fetched from
github.com,arxiv.org,youtube.com, andx.com. These are recognized as established services and repositories. - [CREDENTIALS_UNSAFE]: The skill provides instructions for accessing sensitive local browser data to reach authenticated content.
SKILL.mdmentions the use of--cookies-from-browser chrometo access login-gated content. This allows the script to read the user's local browser session cookies, which are sensitive credentials.
Audit Metadata