article
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of official AI CLI tools from trusted organizations.
- Evidence:
npm install -g @anthropic-ai/claude-cliandpip install google-generativeaiinSKILL.md. - [COMMAND_EXECUTION]: The skill uses local shell commands to execute AI queries and read files.
- Evidence: Execution of
claude,gemini, andcatcommands throughoutSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The content enhancement features read data from
draft.mdand interpolate it directly into AI prompts, which could allow malicious instructions within those files to manipulate agent behavior. - Ingestion points:
draft.md(via shell variableARTICLE) inSKILL.md. - Boundary markers: Absent; data is placed directly into the prompt string without delimiters.
- Capability inventory: Includes network-capable CLI model invocation (
gemini). - Sanitization: Absent; no escaping or filtering is applied to the file content before interpolation.
Audit Metadata