cli-anything-iterm2

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data by allowing the agent to read live terminal output, scrollback history, and session snapshots. This creates a surface for indirect prompt injection where malicious instructions embedded in terminal output (e.g., from a website the user visits or a file they cat) could influence the agent's actions.
  • Ingestion points: Found in SKILL.md via commands such as session screen, session scrollback, and app snapshot.
  • Boundary markers: The documentation does not specify the use of delimiters or clear instructions for the agent to ignore potentially malicious content within terminal data.
  • Capability inventory: The agent has extensive capabilities including executing shell commands (session send), modifying app preferences (pref), and managing tmux sessions.
  • Sanitization: No explicit sanitization or filtering of terminal output is documented to protect against embedded instructions.
  • [COMMAND_EXECUTION]: The skill's primary purpose is to send text and commands to active terminal sessions using session send. While this is the intended behavior, it gives the agent significant control over the local development environment and filesystem through the terminal interface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:21 PM