deep-research
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands to interact with the host system's clipboard. Evidence includes the use of
pbcopy,xclip,wl-copy, andclip.exewithin a shell pipe chain to transfer generated content to the clipboard. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local project files and user input to construct a prompt, creating a surface for indirect instructions to influence agent behavior.
- Ingestion points: Reads project configuration files including
package.json,requirements.txt, andCargo.tomlas instructed inSKILL.mdstep 2. - Boundary markers: Absent. There are no instructions to the agent to use delimiters or ignore potential instructions embedded within the configuration files it reads.
- Capability inventory: The skill possesses the capability to execute shell commands to modify the system clipboard.
- Sanitization: Absent. Content from the external configuration files is interpolated directly into the prompt structure without escaping, validation, or filtering.
Audit Metadata