agent-definition-fix
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The SKILL.md file instructs users to execute a local Python script fix_agent_definitions.py to perform repairs. \n- [DATA_EXPOSURE]: The script fix_agent_definitions.py reads and modifies files in the ~/.gemini/agents/ directory. While this directory contains agent instructions and configurations, no credentials or private keys are targeted. \n- [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to programmatically modify files that contain agent instructions, which represents an attack surface for indirect prompt injection. \n
- Ingestion points: The script reads all .md files in the ~/.gemini/agents/ directory. \n
- Boundary markers: No boundary markers or specific ignore instructions are used when processing the files. \n
- Capability inventory: The script has file-write capabilities (open(filepath, 'w')) used to update agent definition content. \n
- Sanitization: Content is modified using specific regular expressions for 'color' and 'tools' keys, but the rest of the file content is not validated or sanitized.
Audit Metadata