ljg-learn
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a shell command (
date +%Y%m%dT%H%M%S) to generate a timestamp for use in a filename. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input to define the concept being analyzed, which is then used to generate a file path and content.
- Ingestion points: The user provides a concept name (e.g., via
/ljg-learn {concept}) which is interpolated into the filename~/Documents/notes/{timestamp}--概念解剖-{概念名}__concept.organd the file content (SKILL.md). - Boundary markers: The skill does not define specific delimiters or instructions to treat the user-supplied concept name as data only.
- Capability inventory: The skill has the capability to write files to the local filesystem and execute shell commands to fetch metadata.
- Sanitization: There is no evidence of sanitization or validation for the concept name. A malicious user could provide a concept name containing path traversal sequences (e.g.,
../../../tmp/evil) to write files outside of the intended directory.
Audit Metadata