gifgrep
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill specifies installation procedures for the
gifgreputility from a public GitHub repository using Homebrew (steipete/tap/gifgrep) or the Go toolchain (github.com/steipete/gifgrep/cmd/gifgrep@latest).\n- [COMMAND_EXECUTION]: The skill utilizes thegifgrepcommand-line tool to perform GIF searches, download files to the local system, and generate image sheets or stills.\n- [PROMPT_INJECTION]: The skill is subject to indirect prompt injection via external metadata from GIF providers.\n - Ingestion points: Results and metadata from Tenor and Giphy APIs processed by the
gifgrepcommand (SKILL.md).\n - Boundary markers: None identified.\n
- Capability inventory: Shell command execution, file system writes to
~/Downloads, and image processing capabilities.\n - Sanitization: No explicit sanitization or validation of API-provided strings is documented.
Audit Metadata