fish-shell
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for ingesting and processing external data, which could be exploited via indirect prompt injection if the agent processes untrusted content (e.g., from files or command outputs) using these shell structures.
- Ingestion points:
SKILL.mddocuments input mechanisms such asread -l line,$argv(command-line arguments), and command substitution(cmd)used within shell scripts. - Boundary markers: The instructions do not define specific delimiters or "ignore instructions" markers to separate untrusted data from shell logic.
- Capability inventory: The skill leverages high-privilege capabilities including
run_command(shell execution),write_to_file,edit, and the ability to source dynamic content. - Sanitization: While the skill mentions the
string escapeutility for shell-escaping or URL-encoding, it does not mandate its use for all interpolated variables or untrusted inputs. - [DYNAMIC_EXECUTION]: The documentation includes patterns for dynamic code evaluation at runtime.
- Evidence: The skill highlights the
cmd | sourcepattern as an idiomatic replacement for Bash'ssource <(cmd), which allows the shell to execute the output of an arbitrary command as executable shell script code. - [COMMAND_EXECUTION]: The skill is designed to guide the agent in executing shell commands and writing scripts.
- Evidence: It provides comprehensive rules for using
run_commandand shell built-ins to interact with the host environment, which is a powerful capability that must be monitored for misuse.
Audit Metadata