headline-card

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions to execute shell commands (sed, grep) for manipulating local SVG image files.
  • [COMMAND_EXECUTION]: A command in the widow-check section dynamically resolves a file path using a wildcard search in a hidden plugin cache directory (~/.claude/plugins/cache/tinymist-plugin/...) and executes the resulting Python script. This facilitates the execution of code from a path that may contain unverified plugin content.
  • [PROMPT_INJECTION]: The skill establishes a workflow where data is ingested from external web searches to populate presentation fields. This ingestion of untrusted external content creates a surface for indirect prompt injection.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 06:30 AM
Security Audit — agent-trust-hub — headline-card