desktop-gnome

Warn

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill employs extreme context stuffing across eight reference files (e.g., architecture-patterns.md, error-handling.md, testing-strategies.md). Each file repeats identical technical paragraphs and code snippets approximately 150 times.
  • This technique is designed to fill the agent's context window with redundant technical data to bias the AI's persona and potentially dilute its operational instructions.
  • The files use deceptive framing, claiming to be "strictly intended for Staff+ Engineers" to manipulate the AI's internal reasoning and output style.
  • [COMMAND_EXECUTION]: The documentation in gnome-dev-setup.md provides shell commands for the user to install system packages and flatpak runtimes using administrative privileges (sudo apt install).
  • While these are standard setup steps for the GNOME platform, users should verify any command requiring sudo before execution as it modifies the host system environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 12:21 PM
Security Audit — agent-trust-hub — desktop-gnome