sota-cli-ux
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill is entirely documentation-based and does not include any executable scripts, binaries, or configuration files that execute code.
- [SAFE]: All instructional content was reviewed and found to be safe. It explicitly recommends security best practices, such as avoiding secrets in command-line arguments and requiring clear telemetry disclosure. No signs of obfuscation, exfiltration, or unauthorized persistence were found.
- [PROMPT_INJECTION]: The instructions for auditing external CLI tools create a surface for indirect prompt injection from the audited tool's output.
- Ingestion points: External CLI tool output (stdout/stderr) processed during audit probes in SKILL.md.
- Boundary markers: None identified in the audit workflow.
- Capability inventory: Execution of shell commands to run the CLI tools being audited.
- Sanitization: No specific sanitization or escaping is mentioned for tool output processing.
Audit Metadata