helmor-cli
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and manage data such as local files, conversation histories, and GitHub repository content which could potentially contain malicious instructions.
- Ingestion points: Data enters the agent's context through subcommands like
helmor filesandhelmor sessionas referenced inSKILL.md. - Boundary markers: The provided instructions do not include the use of explicit delimiters or protective prompts to mitigate instructions embedded in the ingested data.
- Capability inventory: The skill can execute various CLI subcommands, perform file system operations (read/write/stage), and dispatch tasks to other agents via the
helmor sendcommand. - Sanitization: There is no evidence of sanitization or validation protocols for data retrieved from external repositories or session logs.
- [DYNAMIC_EXECUTION]: The skill includes functionality to inspect and manage scripts within a repository environment.
- Evidence: The
helmor scriptscommand group is used to handle repo-level setup, run, and archive scripts, as detailed inSKILL.mdandreferences/helmor-help.md. - Context: This represents a script management capability common in development tools, though it allows the agent to interact with executable content within the user's workspace.
Audit Metadata