nushell-craft
Pass
Audited by Gen Agent Trust Hub on Feb 28, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates the ingestion and analysis of untrusted user-provided Nushell scripts, which establishes an indirect prompt injection surface. -- Ingestion points: User-provided .nu scripts, modules, and Bash-to-Nushell conversion requests are processed via SKILL.md and various reference files. -- Boundary markers: The skill includes extensive documentation for the agent to distinguish between code-as-data and executable instructions, though it lacks enforced technical delimiters within the skill files. -- Capability inventory: Documentation within the skill references the use of external Nushell MCP tools for code evaluation and execution. -- Sanitization: The skill itself serves as a guide for sanitization, defining patterns for path validation and injection prevention that the agent is instructed to implement.
- [EXTERNAL_DOWNLOADS]: The skill provides installation instructions involving a remote repository owned by the author. -- Evidence: github.com/hustcer/nushell-craft.git is referenced for installation via git clone.
Audit Metadata