pihole-blocklist
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
pihole-blocklist-sources.mdfile contains a curated list of over 50 external URLs for blocklists hosted on GitHub, Amazon S3, and JSDelivr. These are used as reference data for the agent's evaluation tasks. - [PROMPT_INJECTION]: The skill is designed to ingest untrusted data from external blocklist URLs and user input. This inherent vulnerability surface (Indirect Prompt Injection) could allow malicious content within a blocklist to attempt to override the agent's evaluation criteria, though the impact is limited by the lack of sensitive capabilities or tools.
- [SAFE]: The skill exposes the author's local absolute file paths and an internal network IP address (192.168.0.101) in the documentation. This is categorized as a low-risk information disclosure of the developer's environment rather than a security vulnerability.
- [NO_CODE]: The skill consists entirely of Markdown instructions and reference data; it does not contain any executable scripts or tool configurations.
Audit Metadata