printing-press-output-review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a CLI tool
cli-printing-press scorecardto generate diagnostic JSON data from the target directory. - [DYNAMIC_EXECUTION]: The agent is instructed that it may invoke the binary found at
$CLI_DIR/<cli-name>-pp-clito verify findings or gather additional output evidence. - [INDIRECT_PROMPT_INJECTION]: The skill asks an agent to process sampled command outputs which are untrusted data and could contain malicious instructions.
- Ingestion points: The agent reads data from
/tmp/output-review-livecheck.json(sampled CLI stdout) and$CLI_DIR/research.json. - Boundary markers: The prompt to the agent does not include specific delimiters or 'ignore' instructions for the sampled content.
- Capability inventory: The agent has access to the Bash tool and is explicitly permitted to execute the local CLI binary.
- Sanitization: No filtering or sanitization of the CLI output is performed before it is presented to the agent for analysis.
Audit Metadata