last30days
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches and installs several CLI tools to facilitate data retrieval, including
yt-dlpfor YouTube content, and specialized Printing Press utilities for news and research sources (arXiv, Techmeme). These are sourced from well-known repositories or the author's own library. - [REMOTE_CODE_EXECUTION]: The skill provides instructions or automates the installation of the Grok CLI using a shell script from
x.ai. Asx.aiis the established service provider for the Grok AI, this is considered a safe and intended operation for enabling the skill's features. - [COMMAND_EXECUTION]: External binaries and scripts (Node.js, Python, CLIs) are invoked using the
subprocessmodule. Arguments are passed as lists to prevent shell injection, and process groups are managed to ensure clean termination on timeouts. - [DATA_EXFILTRATION]: The skill includes an optional hosted mode that sends search queries to a user-defined remote API. It also supports publishing HTML briefs to the
ht-ml.appservice. Both features are opt-in and transparent to the user. Centralized HTTP handling includes redaction of secrets from outgoing logs. - [CREDENTIALS_UNSAFE]: To provide zero-config authentication for X.com and Truth Social, the skill can extract session cookies from local browser databases (Chrome, Brave, Firefox, Safari) on macOS and Linux. This access is targeted specifically to the required domains and cookies, and values are explicitly excluded from logs. It also supports reading from macOS Keychain and the 'pass' password manager.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the public internet. It implements defensive 'evidence envelopes' (
<untrusted_content>tags) and provides clear instructions to the model to treat this content as data rather than instructions, mitigating the risk of the model obeying malicious commands embedded in search results.
Audit Metadata