clipboard

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The run.sh script executes xclip to interact with the system clipboard. It also executes a secondary script, copy-file-to-clipboard.sh, located in a sibling directory (../clipboard-file/).
  • [DATA_EXPOSURE]: The skill by design reads and writes data to the system clipboard. This is the primary purpose of the skill and is triggered only by explicit user requests to "copy to clipboard".
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided file paths and text for the clipboard. While it does not include sanitization logic in the provided run.sh script, the risk is classified as low as it uses standard shell practices and handles input as arguments to xclip or the delegated copy script.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:59 PM
Security Audit — agent-trust-hub — clipboard