klh-cli-speed-tools

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill enables an attack surface for indirect prompt injection by instructing the agent to search through and read external file contents.
  • Ingestion points: Search results from rg and fd, and file contents displayed via bat (SKILL.md).
  • Boundary markers: Absent; there are no specific instructions or delimiters used to ensure the agent ignores or sanitizes instructions embedded within the files it reads.
  • Capability inventory: The skill provides instructions for read-only file system operations and does not include scripts that perform network requests or file writes (SKILL.md).
  • Sanitization: Absent; the content retrieved from the file system is processed by the agent without any explicit sanitization or filtering logic.
  • [COMMAND_EXECUTION]: The skill provides a set of instructions for the agent to execute shell commands to interact with the environment.
  • Evidence: Commands and usage examples for eza, rg, fd, bat, fzf, and fkill are provided in the documentation (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:41 AM
Security Audit — agent-trust-hub — klh-cli-speed-tools