file-organizer
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local shell commands including
ls,find,du,mkdir, andmvto perform its primary function of file organization. These commands are executed locally and are intended to operate on user-specified directories. - [DATA_EXFILTRATION]: Analysis confirms there are no network operations, external downloads, or exfiltration patterns. The skill operates entirely on the local file system.
- [PROMPT_INJECTION]: The instructions do not contain any patterns intended to bypass safety filters or override agent behavior. It includes best practices such as requiring user confirmation before destructive actions like deleting duplicates.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted data in the form of filenames and file metadata during directory analysis. However, the impact is low as the agent is instructed to summarize findings and seek explicit user approval for a plan before executing any changes.
- Ingestion points: Target directory file metadata and filenames (SKILL.md, Step 2).
- Boundary markers: The instructions mandate presenting an 'Organization Plan' to the user before execution, acting as a human-in-the-loop validation step.
- Capability inventory: Includes
ls,find,du,mkdir, andmvcommands. - Sanitization: Standard shell command templates are provided; the agent is relied upon to correctly handle paths and filenames.
Audit Metadata