herdr
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of arbitrary commands within terminal sessions via
herdr pane runandherdr agent prompt. This capability is intended for tool operation but presents a risk if the agent is manipulated into executing unintended commands. - [PROMPT_INJECTION]: The skill exposes the agent to indirect prompt injection. 1. Ingestion points: The agent is instructed to read terminal content using
herdr agent readandherdr pane read(SKILL.md). 2. Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the skill instructions. 3. Capability inventory: The agent has access to powerful commands includingherdr pane run,herdr agent prompt, andherdr agent send-keys(SKILL.md). 4. Sanitization: There are no explicit sanitization or validation steps provided for the data ingested from terminal panes. This combination allows external data to potentially influence the agent's behavior and trigger its command execution capabilities.
Audit Metadata