skills/johnlindquist/claude/think/Gen Agent Trust Hub

think

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to construct and execute shell commands by interpolating user-provided text (e.g., [Your problem], [IDEA], [SYMPTOM]) directly into double-quoted strings for the gemini CLI tool. This pattern is vulnerable to shell command injection if the input contains shell metacharacters such as backticks (`), dollar-parentheses ($()), or semicolons (;).
  • Evidence: Multiple examples in SKILL.md using the pattern: gemini -m pro -o text -e "" "... [Your problem] ...".
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the google-generativeai package from the official Python Package Index (PyPI). This is a trusted source from a well-known organization.
  • Evidence: SKILL.md contains the command pip install google-generativeai.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data (problems, ideas, code symptoms) and interpolates it into prompts without using boundary markers or sanitization. This allows malicious instructions embedded in the processed data to potentially influence the reasoning output of the Gemini model.
  • Ingestion points: SKILL.md templates for Deep Analysis, Quick Think, Challenge an Idea, and Debugging Strategy.
  • Boundary markers: Absent; data is placed under simple headers like PROBLEM: or IDEA:.
  • Capability inventory: Executes shell commands via the gemini CLI tool.
  • Sanitization: None provided in the templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:14 AM
Security Audit — agent-trust-hub — think