kitty-terminal

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate tool for terminal automation and session management, using standard commands and local resources.
  • [COMMAND_EXECUTION]: The skill utilizes a dynamic context injection pattern (!man ...) to generate an up-to-date list of manual pages from the local installation. This is a benign use of shell execution for documentation purposes.
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection where untrusted terminal state data (e.g., window titles, user variables) enters the agent context via kitten @ ls output as described in SKILL.md. While boundary markers and sanitization are absent, the skill's capabilities (process launching, window manipulation) are standard for terminal management, resulting in a low-risk profile.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 06:09 PM
Security Audit — agent-trust-hub — kitty-terminal