cli-anything-seaclip

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves project data (issue titles, descriptions, and activity) from external sources that could contain untrusted instructions. 1. Ingestion points: SeaClip-Lite HTTP API (localhost:5200) and local SQLite database mentioned in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Subprocess execution of cli-anything-seaclip commands as defined in SKILL.md. 4. Sanitization: Absent.
  • [COMMAND_EXECUTION]: The skill facilitates the use of a command-line utility for project management tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:21 PM
Security Audit — agent-trust-hub — cli-anything-seaclip