skills/halo-dev/cli/halo-cli-content/Gen Agent Trust Hub

halo-cli-content

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to interact with the halo CLI binary to perform content management tasks such as listing, creating, and exporting posts and pages.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-controlled data that is interpolated into shell commands executed by the halo binary, which constitutes a vulnerability surface for indirect prompt injection.
  • Ingestion points: User-provided inputs for --title, --content, --excerpt, and file paths for --file in SKILL.md.
  • Boundary markers: Absent; there are no instructions for the agent to use delimiters or ignore potentially malicious instructions embedded in user content.
  • Capability inventory: The skill utilizes shell command execution via the halo CLI and performs local file system operations (read/write) for importing and exporting content as described in SKILL.md.
  • Sanitization: Absent; the skill does not specify any sanitization or validation logic for the content it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 06:33 AM
Security Audit — agent-trust-hub — halo-cli-content