skills/johnlindquist/claude/pipeline/Gen Agent Trust Hub

pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines several workflows that ingest untrusted data from the file system or user input and interpolate it directly into AI prompts.
  • Ingestion points: The skill reads file contents (cat "$FILE"), command line arguments ($1), and research topics ($TOPIC) which are then passed to the gemini and claude CLI tools.
  • Capability inventory: The skill has the capability to read any file accessible to the user, execute npx commands (like eslint and tsc), and invoke external AI models.
  • Boundary markers: The prompts do not use structural delimiters (e.g., XML tags or triple backticks) to separate instructions from the data being processed, nor do they include warnings to the model to ignore embedded instructions.
  • Sanitization: No sanitization or validation is performed on the input data before it is sent to the AI models.
  • [COMMAND_EXECUTION]: The skill uses shell scripts to orchestrate complex tasks. This includes executing local development tools and reading from the file system.
  • Evidence: Examples in SKILL.md use cat to read source code, echo to pipe data, and npx to run linters and type checkers on project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:25 PM
Security Audit — agent-trust-hub — pipeline