clipboard
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
run.shscript executesxclipto interact with the system clipboard. It also executes a secondary script,copy-file-to-clipboard.sh, located in a sibling directory (../clipboard-file/). - [DATA_EXPOSURE]: The skill by design reads and writes data to the system clipboard. This is the primary purpose of the skill and is triggered only by explicit user requests to "copy to clipboard".
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided file paths and text for the clipboard. While it does not include sanitization logic in the provided
run.shscript, the risk is classified as low as it uses standard shell practices and handles input as arguments toxclipor the delegated copy script.
Audit Metadata