skills/kangarooking/x-skills/x-filter/Gen Agent Trust Hub

x-filter

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, including content collected via other tools or raw text provided by the user.
  • Ingestion points: Materials from x-collect output and manual list/raw text inputs in SKILL.md.
  • Boundary markers: Absent. No delimiters or instructions are provided to isolate the content or warn the agent to ignore instructions embedded within the topics.
  • Capability inventory: The skill reads local files (e.g., user-profile.md, rejected_topics.json) and executes local scripts via the shell.
  • Sanitization: Absent. The skill does not provide instructions to sanitize or validate external content before processing.
  • [COMMAND_EXECUTION]: The workflow involves executing local Python scripts where user-controlled variables are interpolated into shell command strings.
  • Evidence: Found command: python ~/.claude/skills/x-create/scripts/x_state.py similarity --against rejected --text "{topic}" --topk 3.
  • Evidence: Found command: python ~/.claude/skills/x-create/scripts/x_state.py reject --topic-json '{"title":"...","reason":"...","stage":"filter"}'.
  • Risk: The {topic} and {topic-json} placeholders are populated with untrusted data. If the input contains shell metacharacters (e.g., backticks or semicolons), it could result in arbitrary command execution on the local system.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 07:34 AM