cli-design
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The design pattern documented in this skill relies on a
next_actionsfield in CLI responses, which provides command templates (HATEOAS) for the agent to execute next. This creates an indirect prompt injection surface where an agent's future actions are directed by the output of a tool, potentially leading to the execution of sensitive commands without explicit user approval. - Ingestion points: The agent ingests structured JSON from tools built according to this specification (e.g.,
joelclaw) as described inSKILL.md. - Boundary markers: The skill does not define specific boundary markers or 'ignore' instructions to prevent the agent from blindly following the suggested
next_actions. - Capability inventory: The skill references capabilities including shell command execution, interaction with Redis pub/sub, and Kubernetes pod management (
kubectl) inSKILL.md. - Sanitization: The design does not specify sanitization, validation, or human-in-the-loop requirements for the parameters or commands provided in the
next_actionsarray.
Audit Metadata