skills/duthaho/skillhub/priorart/Gen Agent Trust Hub

priorart

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to utilize the date +%F command to ensure accurate timestamps are used for file naming and logging. This is a benign use of system utilities for record-keeping.
  • [EXTERNAL_DOWNLOADS]: The agent retrieves repository metadata, download statistics, and project descriptions from established developer services and academic registries, including GitHub, GitLab, PyPI, npm, crates.io, and arXiv. These operations are essential for the skill's research purpose and target well-known platforms.
  • [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes and summarizes content from untrusted external sources.
  • Ingestion points: Step 3 (Search where builders publish) and Step 4 (Trace one layer down) fetch content from external project descriptions and repository leads.
  • Boundary markers: The skill employs a structured Markdown template (references/brief-template.md) to organize the final output, providing some structural separation.
  • Capability inventory: The skill is capable of network-based searching, reading/writing files within the out/priorart/ project directory, and executing basic shell commands for date formatting.
  • Sanitization: The instructions do not specify sanitization or escaping protocols for the content retrieved from external sources before it is interpolated into the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 04:21 PM
Security Audit — agent-trust-hub — priorart