skills/datex/skills/selector-creator/Gen Agent Trust Hub

selector-creator

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the dxs CLI utility and jq for configuration management, including fetching, validating, and updating JSON files on the Datex platform. These are legitimate tools provided by the vendor (SKILL.md).\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes external configuration data (JSON files) from the Datex platform. While it includes validation steps, the processing of untrusted external content represents a surface for indirect prompt injection.\n
  • Ingestion points: Configuration data fetched via dxs configuration get (SKILL.md).\n
  • Boundary markers: The skill recommends using dxs configuration validate before upserting (SKILL.md).\n
  • Capability inventory: Includes shell command execution capabilities via dxs and jq (SKILL.md).\n
  • Sanitization: Uses jq to extract specific JSON fields and relies on platform-native validation commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 01:11 PM
Security Audit — agent-trust-hub — selector-creator