bulk
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface. The skill instructs the agent to read and summarize transcript files generated from external TikTok videos in Step 6. Content within these transcripts could contain malicious instructions designed to influence the agent's behavior during the summarization or indexing phases.
- Ingestion points: The agent reads transcript files from the
transcripts/directory (SKILL.md, Step 6). - Boundary markers: The skill uses a
--- TRANSCRIPT ---separator in the files, but lacks explicit instructions for the agent to ignore or treat the embedded content as untrusted data. - Capability inventory: The agent has access to the
Bashtool and can write files to thesummaries/directory. - Sanitization: Filenames are sanitized via kebab-case conversion, but the transcript content itself is processed without filtering.
- [COMMAND_EXECUTION]: Potential for code injection via string interpolation. In Steps 4 and 5, user-provided inputs like
PROFILE_URL_HEREandLIMIT_OR_NONEare inserted directly into Python string literals inside apython -ccommand. A malformed URL containing single quotes and Python code could lead to arbitrary code execution if the agent does not properly escape the input when generating the command. - [COMMAND_EXECUTION]: Risk of path traversal or unintended file manipulation. The skill uses video metadata (IDs and titles) extracted from external sources to construct file paths for transcripts and summaries. While kebab-case conversion is applied to titles, the video IDs are used directly, which could be exploited if the source metadata is manipulated.
Audit Metadata