klh-cli-speed-tools
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill enables an attack surface for indirect prompt injection by instructing the agent to search through and read external file contents.
- Ingestion points: Search results from
rgandfd, and file contents displayed viabat(SKILL.md). - Boundary markers: Absent; there are no specific instructions or delimiters used to ensure the agent ignores or sanitizes instructions embedded within the files it reads.
- Capability inventory: The skill provides instructions for read-only file system operations and does not include scripts that perform network requests or file writes (SKILL.md).
- Sanitization: Absent; the content retrieved from the file system is processed by the agent without any explicit sanitization or filtering logic.
- [COMMAND_EXECUTION]: The skill provides a set of instructions for the agent to execute shell commands to interact with the environment.
- Evidence: Commands and usage examples for
eza,rg,fd,bat,fzf, andfkillare provided in the documentation (SKILL.md).
Audit Metadata