show-me
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the system's
opencommand to display generated HTML files for complex visual explanations. Evidence: TheSKILL.mdfile contains the instructionopen path/to/show-me-<topic>.htmlto be executed when layout or visual state comparison is needed. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and visualize user-provided technical data, such as code snippets and architectural descriptions, which presents a surface for indirect prompt injection. 1. Ingestion points: User prompts requesting explanations of logic, call trees, component structures, or file layouts (found in
SKILL.mdandevals/cases.yaml). 2. Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the processed data. 3. Capability inventory: The skill can generate text-based diagrams (Mermaid, pseudocode) and standalone HTML files, and it can invoke theopenutility. 4. Sanitization: The instructions do not specify any validation or sanitization steps for the data being visualized.
Audit Metadata