obey
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The instructions utilize absolute directives such as "The Rule," "There are no exceptions," and "Run the user's command verbatim." These commands explicitly instruct the agent to disregard its own reasoning, interpretation, or safety-oriented "improvements" to user-supplied strings, effectively bypassing internal checks that might otherwise identify malicious payloads.
- [COMMAND_EXECUTION]: The skill's primary function is to facilitate the direct execution of shell commands and CLI instructions. By removing the agent's tendency to decompose or validate these commands, it significantly increases the likelihood of executing dangerous commands (e.g., those containing shell metacharacters or malicious arguments) if they are present in the input.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a high-risk pattern for indirect prompt injection by demanding faithful execution of external data.
- Ingestion points: Command strings derived from user input or project context in SKILL.md.
- Boundary markers: Absent; the skill explicitly forbids the agent from altering the input, preventing the use of safety boundaries or sanitization.
- Capability inventory: The skill facilitates arbitrary shell command execution (e.g., pnpm, git).
- Sanitization: Absent; the skill insists on a "Copy, paste, execute" approach with no validation of the command's safety.
Audit Metadata