pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines several workflows that ingest untrusted data from the file system or user input and interpolate it directly into AI prompts.
- Ingestion points: The skill reads file contents (
cat "$FILE"), command line arguments ($1), and research topics ($TOPIC) which are then passed to thegeminiandclaudeCLI tools. - Capability inventory: The skill has the capability to read any file accessible to the user, execute
npxcommands (likeeslintandtsc), and invoke external AI models. - Boundary markers: The prompts do not use structural delimiters (e.g., XML tags or triple backticks) to separate instructions from the data being processed, nor do they include warnings to the model to ignore embedded instructions.
- Sanitization: No sanitization or validation is performed on the input data before it is sent to the AI models.
- [COMMAND_EXECUTION]: The skill uses shell scripts to orchestrate complex tasks. This includes executing local development tools and reading from the file system.
- Evidence: Examples in
SKILL.mdusecatto read source code,echoto pipe data, andnpxto run linters and type checkers on project files.
Audit Metadata