distill
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
run.shscript usesexec bashto invoke a sibling skill entry point (doc2qra/run.sh) and forwards all user-supplied command-line arguments using the"$@"pattern. - [PROMPT_INJECTION]: The skill defines an interface for ingesting external content via flags such as
--file,--url, and--text, creating an indirect prompt injection surface where malicious instructions in processed data could attempt to influence the agent. Ingestion points: Data provided through--file,--url, and--textflags as documented inSKILL.md. Boundary markers: None are present in this shim to delimit external content. Capability inventory: Execution of bash scripts (run.sh) and sourcing of project-level environment files. Sanitization: No validation or sanitization of inputs is performed before they are passed to the downstream skill.
Audit Metadata