take-probe
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill loads and follows instructions from an external file (
probe.md) located in a directory provided via user message.\n - Ingestion point: Reads
<ref>/probe.mdbased on a reference from a message (SKILL.md).\n - Boundary markers: Absent; instructions specify following the file 'verbatim'.\n
- Capability inventory: The agent follows instructions which may use any available tools and executes
check.sh(SKILL.md).\n - Sanitization: Absent; no filtering or validation of the probe content is described.\n- [COMMAND_EXECUTION]: The skill executes a bundled shell script
check.shfor validation.\n - Evidence: 'Run check.sh beside this file.' (SKILL.md).
Audit Metadata