skills/broomva/skills/checkit/Gen Agent Trust Hub

checkit

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local scripts and system tools using parameters derived from external user-provided artifacts.
  • The instructions in SKILL.md specify running python3 scripts/video_ingest.py with a URL and an inferred query as arguments.
  • The skill provides a specific security directive to single-quote these arguments to prevent shell injection attacks from hostile URLs containing metacharacters.
  • It also utilizes gh api to traverse repository trees and ffmpeg for video processing.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface by ingesting and analyzing content from arbitrary external sources, which could contain adversarial instructions.
  • Ingestion points: The agent fetches data from GitHub repositories, research papers (arXiv), social media (X, Instagram), and video platforms (YouTube) as described in SKILL.md and references/checkit-lens.md.
  • Capability inventory: The skill has the ability to execute shell commands via local scripts and write to the agent's internal knowledge base.
  • Boundary markers: The skill requires the agent to declare its inferred intent before processing, providing a level of context, but lacks explicit technical delimiters for the ingested content itself.
  • Sanitization: Shell-level sanitization is performed via quoting, but the content remains subject to LLM interpretation.
  • [EXTERNAL_DOWNLOADS]: The skill references and fetches data from numerous well-known external services for research purposes.
  • Artifacts are fetched from github.com, arxiv.org, youtube.com, and x.com. These are recognized as established services and repositories.
  • [CREDENTIALS_UNSAFE]: The skill provides instructions for accessing sensitive local browser data to reach authenticated content.
  • SKILL.md mentions the use of --cookies-from-browser chrome to access login-gated content. This allows the script to read the user's local browser session cookies, which are sensitive credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:29 PM
Security Audit — agent-trust-hub — checkit