fresh-library-docs
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch untrusted data from external sources including documentation sites, blogs, and GitHub issues via the WebFetch and WebSearch tools in Step 3.
- Ingestion points: External URLs and search results accessed during the library verification process in SKILL.md.
- Boundary markers: The instructions do not define delimiters or provide specific instructions for the agent to ignore potentially malicious instructions embedded in the external content.
- Capability inventory: The skill provides access to Bash (system command execution), WebFetch (network access), and Read/Grep (filesystem access).
- Sanitization: The instructions do not include requirements for sanitizing or filtering data retrieved from the web before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill uses the Bash tool to run system commands such as cat, grep, npm ls, and pip show. These commands are used for legitimate project environment inspection, such as reading manifest files and checking installed package metadata.
- [DYNAMIC_EXECUTION]: The skill employs python -c and node -e to execute code snippets for inspecting library signatures and exports. This dynamic execution is used to verify the availability and structure of local project dependencies.
Audit Metadata