sota-cli-ux

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill is entirely documentation-based and does not include any executable scripts, binaries, or configuration files that execute code.
  • [SAFE]: All instructional content was reviewed and found to be safe. It explicitly recommends security best practices, such as avoiding secrets in command-line arguments and requiring clear telemetry disclosure. No signs of obfuscation, exfiltration, or unauthorized persistence were found.
  • [PROMPT_INJECTION]: The instructions for auditing external CLI tools create a surface for indirect prompt injection from the audited tool's output.
  • Ingestion points: External CLI tool output (stdout/stderr) processed during audit probes in SKILL.md.
  • Boundary markers: None identified in the audit workflow.
  • Capability inventory: Execution of shell commands to run the CLI tools being audited.
  • Sanitization: No specific sanitization or escaping is mentioned for tool output processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 10:17 PM
Security Audit — agent-trust-hub — sota-cli-ux