agent-deep-links

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the PlistBuddy and open commands to verify application capabilities. These are standard system utilities used for their intended purpose in the context of deep-link verification.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface where user-supplied application names and URL schemes are interpolated into shell commands for verification.
  • Ingestion points: Application names and schemes provided by the user or defined in references/deep-link-matrix.md as described in SKILL.md.
  • Boundary markers: None identified.
  • Capability inventory: Metadata inspection via PlistBuddy and application/URL launching via open.
  • Sanitization: No explicit sanitization or input validation logic is present in the instructions.
  • [SAFE]: The documentation links provided in the reference matrix point to official developer resources for VS Code, Cursor, and Visual Studio.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 04:33 PM
Security Audit — agent-trust-hub — agent-deep-links