zsh
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted Zsh scripts and dotfiles which may contain malicious instructions designed to influence the agent.
- Ingestion points: The skill is triggered by and processes .zsh, .zshrc, .zprofile, .zshenv, .zlogin, and .zlogout files, as well as scripts within the ~/dotfiles directory.
- Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the files it reviews.
- Capability inventory: The skill is capable of modifying Zsh scripts and executing syntax checks using the zsh -n command.
- Sanitization: The guide includes safety recommendations such as validating external input before command execution and avoiding the exposure of secrets in logs, which are positive defensive measures.
Audit Metadata