liaison
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to run diagnostic commands includingnpm run build,git status,git log,ls,find, andgrep. These are executed to collect status and metric data from the development environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by reading and summarizing data from potentially untrusted local sources.\n - Ingestion points: The skill ingests text from
git log(commit messages),npm run build(build logs), andgrepresults (TODO comments inwebsite/src/) as defined inSKILL.md.\n - Boundary markers: Absent. The skill uses markdown templates for reporting but lacks specific delimiters or instructions to ignore commands that may be embedded within the summarized data.\n
- Capability inventory: The skill has access to
Bash,Read,Grep, andGlobtools, which allow for command execution and file system interaction.\n - Sanitization: Absent. External content is interpolated directly into the status briefing templates without filtering or validation.
Audit Metadata