gifgrep

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill specifies installation procedures for the gifgrep utility from a public GitHub repository using Homebrew (steipete/tap/gifgrep) or the Go toolchain (github.com/steipete/gifgrep/cmd/gifgrep@latest).\n- [COMMAND_EXECUTION]: The skill utilizes the gifgrep command-line tool to perform GIF searches, download files to the local system, and generate image sheets or stills.\n- [PROMPT_INJECTION]: The skill is subject to indirect prompt injection via external metadata from GIF providers.\n
  • Ingestion points: Results and metadata from Tenor and Giphy APIs processed by the gifgrep command (SKILL.md).\n
  • Boundary markers: None identified.\n
  • Capability inventory: Shell command execution, file system writes to ~/Downloads, and image processing capabilities.\n
  • Sanitization: No explicit sanitization or validation of API-provided strings is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 08:32 AM
Security Audit — agent-trust-hub — gifgrep