skills/celeroncoder/skills/helmor-cli/Gen Agent Trust Hub

helmor-cli

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and manage data such as local files, conversation histories, and GitHub repository content which could potentially contain malicious instructions.
  • Ingestion points: Data enters the agent's context through subcommands like helmor files and helmor session as referenced in SKILL.md.
  • Boundary markers: The provided instructions do not include the use of explicit delimiters or protective prompts to mitigate instructions embedded in the ingested data.
  • Capability inventory: The skill can execute various CLI subcommands, perform file system operations (read/write/stage), and dispatch tasks to other agents via the helmor send command.
  • Sanitization: There is no evidence of sanitization or validation protocols for data retrieved from external repositories or session logs.
  • [DYNAMIC_EXECUTION]: The skill includes functionality to inspect and manage scripts within a repository environment.
  • Evidence: The helmor scripts command group is used to handle repo-level setup, run, and archive scripts, as detailed in SKILL.md and references/helmor-help.md.
  • Context: This represents a script management capability common in development tools, though it allows the agent to interact with executable content within the user's workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — helmor-cli