skills/mabhub/skills/tldr-generator/Gen Agent Trust Hub

tldr-generator

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of internal Node.js and Python scripts to analyze articles and validate generated summaries. This is an expected part of the skill's workflow.
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it processes untrusted markdown content. 1. Ingestion points: Markdown files identified in the workspace are read into the agent's context via scripts. 2. Boundary markers: There are no explicit delimiters or instructions provided to isolate processed content from the agent's core logic. 3. Capability inventory: The agent can execute local scripts and perform file system operations. 4. Sanitization: The skill includes preventative instructions in SKILL.md directing the agent to avoid reproducing sensitive data like tokens or emails in the final output.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 09:07 AM
Security Audit — agent-trust-hub — tldr-generator