skills/oxbshw/watch-skill/the-loop/Gen Agent Trust Hub

the-loop

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents the use of the watch-skill CLI tool via Bash for visual verification tasks. This includes executing user-provided shell commands for launching applications or rendering media, which is a core function of the tool.
  • [PROMPT_INJECTION]: The skill facilitates indirect prompt injection by processing data from external URLs, screen captures, and files. 1. Ingestion points: The watch-skill tool captures content from URLs, windows, and local files. 2. Boundary markers: No explicit delimiters or instructions are documented to distinguish between captured data and agent commands. 3. Capability inventory: The agent can execute Bash commands, creating a potential path for exploitation if external content contains malicious instructions. 4. Sanitization: No sanitization or validation of the ingested external content is mentioned in the skill documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 12:04 AM
Security Audit — agent-trust-hub — the-loop