asking-with-evidence
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill uses
Bashto invoke thewatch-skillutility with user-controlled arguments, a pattern typically associated with command execution risks. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input which is passed to the command-line interface. Ingestion points: user questions and search phrases in SKILL.md. Boundary markers: documentation suggests double-quoting user inputs. Capability inventory: Bash and Read tools. Sanitization: no explicit sanitization logic is provided.
Audit Metadata