bundle
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous shell commands and scripts that utilize standard Unix utilities like
grep,sed,cat, andjq, as well as the GitHub CLI (gh). These are used to parse local files and interact with GitHub Gists. - [DATA_EXFILTRATION]: The primary purpose of the skill is to upload local code snippets to GitHub Gists. While this involves sending data to an external service, it is the intended functionality of the tool and relies on the user's existing GitHub CLI authentication.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it reads and processes external data (local source code files). If the files being bundled contain malicious instructions hidden in comments or strings, they could potentially influence the agent's behavior during the bundling process.
- Ingestion points: Reads local files via
cat,head, andgrepinSKILL.md(e.g.,bundle-file.sh,CLAUDE.mdgenerator). - Boundary markers: The scripts wrap content in Markdown code blocks (e.g., ```typescript), which provides a structural boundary but does not sanitize the content.
- Capability inventory: The skill uses file system read operations and network communication via the
ghtool. - Sanitization: No explicit sanitization or filtering of the code content is performed before bundling.
Audit Metadata