printing-press-output-review

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a CLI tool cli-printing-press scorecard to generate diagnostic JSON data from the target directory.
  • [DYNAMIC_EXECUTION]: The agent is instructed that it may invoke the binary found at $CLI_DIR/<cli-name>-pp-cli to verify findings or gather additional output evidence.
  • [INDIRECT_PROMPT_INJECTION]: The skill asks an agent to process sampled command outputs which are untrusted data and could contain malicious instructions.
  • Ingestion points: The agent reads data from /tmp/output-review-livecheck.json (sampled CLI stdout) and $CLI_DIR/research.json.
  • Boundary markers: The prompt to the agent does not include specific delimiters or 'ignore' instructions for the sampled content.
  • Capability inventory: The agent has access to the Bash tool and is explicitly permitted to execute the local CLI binary.
  • Sanitization: No filtering or sanitization of the CLI output is performed before it is presented to the agent for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:35 PM
Security Audit — agent-trust-hub — printing-press-output-review