command-injection
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill content is strictly educational and analytical, providing instructions for security researchers to audit code for vulnerabilities. Code snippets containing dangerous functions (e.g., exec, system) or exploit payloads (e.g.,
; id) are provided as examples within markdown code blocks for diagnostic purposes and do not represent execution risks to the user or agent. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted source code. While this activity has an inherent risk of indirect prompt injection if the files being audited contain malicious instructions, the skill provides a structured process for analysis that focuses on code patterns, reducing the likelihood of the agent following instructions embedded in the data.
Audit Metadata