ljg-read
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute the
datecommand to generate timestamps for file organization. This is a benign use of system utilities. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external sources, which is its intended purpose. 1. Ingestion points: Text is retrieved via
WebFetch,markdown-proxy, and fileReadoperations. 2. Boundary markers: The skill does not define specific boundaries or ignore-instructions for the external content. 3. Capability inventory: The agent can execute system commands (date) and write to the local file system. 4. Sanitization: No sanitization methods are specified for the ingested content. - [DATA_EXPOSURE]: The skill accesses local files and writes notes to the user's
~/Documents/notes/directory, consistent with its primary function as a reading companion.
Audit Metadata