skills/ericrisco/rsc-harness/eli5/Gen Agent Trust Hub

eli5

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs its stated purpose of creating visual 'Explain Like I'm Five' content without any malicious behavior. It follows a standard pattern for generating and displaying visual aids to the user via HTML.
  • [COMMAND_EXECUTION]: The skill instructions include an open command to display a generated HTML file (eli5-<topic>.html). This is a legitimate use of tool capabilities to fulfill the skill's primary function of providing a visual user interface.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied topics, creating a theoretical attack surface for indirect prompt injection.
  • Ingestion points: The {topic} input and conversation context used to generate the HTML page.
  • Boundary markers: Not explicitly defined in the instructions.
  • Capability inventory: File write operations and the open command for local file display.
  • Sanitization: No specific sanitization of the topic name is mentioned. Despite the presence of an ingestion surface, the risk is negligible as the skill lacks network exfiltration capabilities, sensitive file access, or high-privilege command execution. The output is a simple explanatory page for the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:19 AM
Security Audit — agent-trust-hub — eli5