x-filter
Warn
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, including content collected via other tools or raw text provided by the user.
- Ingestion points: Materials from
x-collectoutput and manual list/raw text inputs inSKILL.md. - Boundary markers: Absent. No delimiters or instructions are provided to isolate the content or warn the agent to ignore instructions embedded within the topics.
- Capability inventory: The skill reads local files (e.g.,
user-profile.md,rejected_topics.json) and executes local scripts via the shell. - Sanitization: Absent. The skill does not provide instructions to sanitize or validate external content before processing.
- [COMMAND_EXECUTION]: The workflow involves executing local Python scripts where user-controlled variables are interpolated into shell command strings.
- Evidence: Found command:
python ~/.claude/skills/x-create/scripts/x_state.py similarity --against rejected --text "{topic}" --topk 3. - Evidence: Found command:
python ~/.claude/skills/x-create/scripts/x_state.py reject --topic-json '{"title":"...","reason":"...","stage":"filter"}'. - Risk: The
{topic}and{topic-json}placeholders are populated with untrusted data. If the input contains shell metacharacters (e.g., backticks or semicolons), it could result in arbitrary command execution on the local system.
Audit Metadata