stashr
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
stashrCLI tool to perform various library operations such as searching, retrieving content, and managing collection states. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes potentially untrusted data from external sources, specifically the user's saved bookmarks and crawled web content.
- Ingestion points: Full content and text snippets are retrieved via the
search,fetch, andstashr getcommands as described inSKILL.md. - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following instructions embedded within the fetched bookmark content.
- Capability inventory: The skill has write and delete capabilities, including
save_bookmark,update_bookmark, andmanage_collection(which includes deletion), though collection deletion requires explicit user confirmation. - Sanitization: Content is converted to Markdown for processing, but no specific sanitization or filtering logic for prompt injection is mentioned.
Audit Metadata