computer
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to bridge local services to remote sandboxes, creating a vulnerability surface where untrusted data could influence the agent.
- Ingestion points: Data originating from local services exposed through the ngrok tunnel (SKILL.md).
- Boundary markers: None described for delimiting or filtering data received via the tunnel.
- Capability inventory: Facilitates remote access to local system services.
- Sanitization: No sanitization or validation mechanisms are described for the data stream.
- [NO_CODE]: The analyzed skill file consists solely of YAML metadata and documentation. No executable scripts, command logic, or implementation details were provided for review.
Audit Metadata