halo-cli-content
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to interact with the
haloCLI binary to perform content management tasks such as listing, creating, and exporting posts and pages. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-controlled data that is interpolated into shell commands executed by the
halobinary, which constitutes a vulnerability surface for indirect prompt injection. - Ingestion points: User-provided inputs for
--title,--content,--excerpt, and file paths for--filein SKILL.md. - Boundary markers: Absent; there are no instructions for the agent to use delimiters or ignore potentially malicious instructions embedded in user content.
- Capability inventory: The skill utilizes shell command execution via the
haloCLI and performs local file system operations (read/write) for importing and exporting content as described in SKILL.md. - Sanitization: Absent; the skill does not specify any sanitization or validation logic for the content it processes.
Audit Metadata