stashr

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the stashr CLI tool to perform various library operations such as searching, retrieving content, and managing collection states.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes potentially untrusted data from external sources, specifically the user's saved bookmarks and crawled web content.
  • Ingestion points: Full content and text snippets are retrieved via the search, fetch, and stashr get commands as described in SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following instructions embedded within the fetched bookmark content.
  • Capability inventory: The skill has write and delete capabilities, including save_bookmark, update_bookmark, and manage_collection (which includes deletion), though collection deletion requires explicit user confirmation.
  • Sanitization: Content is converted to Markdown for processing, but no specific sanitization or filtering logic for prompt injection is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:14 PM
Security Audit — agent-trust-hub — stashr