distill

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The run.sh script uses exec bash to invoke a sibling skill entry point (doc2qra/run.sh) and forwards all user-supplied command-line arguments using the "$@" pattern.
  • [PROMPT_INJECTION]: The skill defines an interface for ingesting external content via flags such as --file, --url, and --text, creating an indirect prompt injection surface where malicious instructions in processed data could attempt to influence the agent. Ingestion points: Data provided through --file, --url, and --text flags as documented in SKILL.md. Boundary markers: None are present in this shim to delimit external content. Capability inventory: Execution of bash scripts (run.sh) and sourcing of project-level environment files. Sanitization: No validation or sanitization of inputs is performed before they are passed to the downstream skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — distill