stuck
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines several prompt templates that ingest untrusted content such as code snippets, error logs, and user-provided problem descriptions. This data is interpolated directly into prompts for the Gemini model without explicit sanitization or instructions to ignore embedded commands.
- Ingestion points: Placeholders for code, error logs, and problem descriptions are present throughout
SKILL.md(e.g.,[paste code],[describe problem]). - Boundary markers: The templates utilize markdown code blocks and structured labels like
CODE:andERROR:, but lack specific instructions to the model to disregard instructions contained within the user-provided data. - Capability inventory: The skill utilizes the
geminiCLI for processing these prompts and standard shell commands for project maintenance. - Sanitization: No input validation or escaping is applied to the untrusted data before it is sent to the LLM.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute various shell commands for environment verification and troubleshooting, including
git bisect,node,npm, andgh. Notably, it includes a command to recursively remove thenode_modulesdirectory andpackage-lock.jsonfile as part of a clean reinstallation process. - [EXTERNAL_DOWNLOADS]: The escalation workflow includes the use of
npm install, which retrieves and installs third-party software packages from the public NPM registry.
Audit Metadata