skills/decocms/studio/file-reading/Gen Agent Trust Hub

file-reading

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands like cat, jq, and column, as well as specific Python extraction scripts located in internal directories (e.g., org/public/core/pdf/extract.py). This functionality assumes the execution environment safely handles file paths provided by users.
  • [PROMPT_INJECTION]: The skill displays an indirect prompt injection surface by ingesting and processing content from untrusted external files. Ingestion points: Content extracted from files provided by the user. Boundary markers: No delimiters or instructions are provided to the agent to ignore commands or instructions embedded within the file content. Capability inventory: Access to system utilities and internal scripts for file reading. Sanitization: There is no evidence of sanitization or escaping of the file content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 01:01 PM
Security Audit — agent-trust-hub — file-reading