f1-test-drive
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill involves the execution of local shell commands and scripts (e.g.,
./f1,bun run apps/f1/server.ts) to manage testing environments, start server processes, and interact with the system APIs. - [INDIRECT_PROMPT_INJECTION]: The skill defines processes for ingesting user-provided input, such as issue descriptions and chat messages, into agent sessions.
- Ingestion points: External data is accepted via command-line arguments such as
--title,--description, and--textin theSKILL.mdfile. - Boundary markers: No delimiters or safety warnings for embedded instructions are identified in the protocol.
- Capability inventory: The skill has the capability to execute local scripts, start server processes, and manage file system paths under
/tmpand the agent's home directory. - Sanitization: There is no description of explicit sanitization, escaping, or validation of the input content prior to processing.
Audit Metadata