skills/ericrisco/rsc-harness/show-me/Gen Agent Trust Hub

show-me

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the system's open command to display generated HTML files for complex visual explanations. Evidence: The SKILL.md file contains the instruction open path/to/show-me-<topic>.html to be executed when layout or visual state comparison is needed.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and visualize user-provided technical data, such as code snippets and architectural descriptions, which presents a surface for indirect prompt injection. 1. Ingestion points: User prompts requesting explanations of logic, call trees, component structures, or file layouts (found in SKILL.md and evals/cases.yaml). 2. Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the processed data. 3. Capability inventory: The skill can generate text-based diagrams (Mermaid, pseudocode) and standalone HTML files, and it can invoke the open utility. 4. Sanitization: The instructions do not specify any validation or sanitization steps for the data being visualized.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — show-me