probe
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool in Phase 2 to execute user-defined or agent-generated probe steps. This allows the execution of arbitrary commands within the host environment as part of its core debugging functionality.
- [PROMPT_INJECTION]: The skill processes potentially untrusted data from arguments and handoff files (e.g., probe-to-probe-llm.md) that can influence the agent's behavior. Ingestion points: Hypotheses and context loaded from files and arguments in SKILL.md. Boundary markers: The skill lacks explicit separators to distinguish data from instructions. Capability inventory: Access to Bash, Write, Read, WebSearch, and WebFetch tools. Sanitization: There is no evidence of validation or sanitization for the inputs being loaded.
Audit Metadata