indices-run-operations
Pass
Audited by Gen Agent Trust Hub on Mar 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill provides legitimate documentation and troubleshooting steps for the Indices CLI tool.
- [COMMAND_EXECUTION]: The skill documents the use of the
indicesCLI and thecargobuild tool. These operations are intended for managing and troubleshooting the vendor's software and do not involve unauthorized privilege escalation or execution of untrusted remote code. - [PROMPT_INJECTION]: The skill facilitates the ingestion of logs and data from the Indices service (e.g., via
indices runs logs). This represents an indirect prompt injection surface where external data enters the agent's context. However, this is inherent to the tool's purpose of monitoring task execution. - Ingestion points: Output from
indices runs logsandindices runs get, and local file input via--fileor stdin (SKILL.md) - Boundary markers: Absent
- Capability inventory: Command execution via the
indicesCLI andcargotools (SKILL.md) - Sanitization: Absent
Audit Metadata