context-mode
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill introduces a potential indirect prompt injection vulnerability surface because it processes untrusted inputs using powerful runtime execution tools without explicit boundary isolation.
- Ingestion points: External files, application logs, transaction CSVs, and remote web documentation are ingested via tools like
ctx_execute_fileandctx_fetch_and_indexas documented in SKILL.md and the references directory. - Boundary markers: Absent; no specific boundary delimiters or safety prompts are defined to isolate data text from agent instructions.
- Capability inventory: The skill utilizes extensive capabilities, including arbitrary JavaScript, Python, and Shell script execution through
ctx_executeandctx_execute_filealongside Bash package mutations. - Sanitization: Absent; data fields and file contents are loaded and parsed directly within scripts without structural escaping or pre-validation.
- [DYNAMIC_EXECUTION]: The skill relies on runtime script generation and execution to filter and summarize large outputs.
- Evidence: Rules and decision trees across SKILL.md and pattern reference guides instruct the agent to dynamically write and execute custom code blocks based on the data source type (e.g., JavaScript for APIs, Python for CSVs, Shell for log piping). This capability is core to the skill's utility but represents a dynamic execution model.
Audit Metadata