utm-link-generator
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data to generate UTM parameters and registry entries. Ingestion points: Workflow Step 1 in SKILL.md and bulk processing in references/bulk-and-registry-ops.md. Boundary markers: Absent; user input is not explicitly delimited. Capability inventory: The skill uses Bash, Read, and Write tools. Sanitization: Normalization rules in SKILL.md filter non-alphanumeric characters for UTM parameters, providing partial mitigation.
- [COMMAND_EXECUTION]: The skill employs the Bash tool for registry auditing and exporting. The processing of user-controlled strings within a shell environment poses a potential risk of command injection.
Audit Metadata