repo
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple shell commands to inspect directory structures and file contents, including
tree,grep,find,cat, andjq. These operations are localized and consistent with the skill's stated purpose of repository context generation. - [INDIRECT_PROMPT_INJECTION]: The skill reads untrusted data from the local repository (source code, configuration files) and interpolates it into prompts for the
geminiCLI tool. This creates a surface where malicious instructions embedded in source code comments or metadata could influence the AI's output. - Ingestion points: Reads contents of
package.json,src/*.ts, andsrc/*.tsxviacatandgrep(SKILL.md lines 146, 168, 185, 203). - Boundary markers: The prompts use simple headers (e.g., "Structure:", "package.json:") but lack strict delimiters or explicit instructions to the AI to ignore embedded commands within the ingested data.
- Capability inventory: The skill has the capability to execute shell commands and write to local files (e.g.,
CONTEXT.md). - Sanitization: There is no evidence of sanitization or escaping of the file content before it is passed to the
geminitool.
Audit Metadata