skills/narumiruna/skills/herdr/Gen Agent Trust Hub

herdr

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of arbitrary commands within terminal sessions via herdr pane run and herdr agent prompt. This capability is intended for tool operation but presents a risk if the agent is manipulated into executing unintended commands.
  • [PROMPT_INJECTION]: The skill exposes the agent to indirect prompt injection. 1. Ingestion points: The agent is instructed to read terminal content using herdr agent read and herdr pane read (SKILL.md). 2. Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the skill instructions. 3. Capability inventory: The agent has access to powerful commands including herdr pane run, herdr agent prompt, and herdr agent send-keys (SKILL.md). 4. Sanitization: There are no explicit sanitization or validation steps provided for the data ingested from terminal panes. This combination allows external data to potentially influence the agent's behavior and trigger its command execution capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 03:32 PM
Security Audit — agent-trust-hub — herdr