paniolo-qmd
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
pnpm run qmdcommands to search, retrieve, and re-index workspace data.\n- [EXTERNAL_DOWNLOADS]: The skill installs author-managed binaries (@paniolo/lasso-*) viapnpmto enable core search functionality.\n- [PROMPT_INJECTION]: An indirect prompt injection surface is present as the skill retrieves untrusted data from the workspace for agent consumption.\n - Ingestion points: Workspace markdown files and documentation accessed via
qmd get(SKILL.md).\n - Boundary markers: No delimiters are specified to isolate retrieved content.\n
- Capability inventory: Shell command execution via
pnpm(SKILL.md).\n - Sanitization: No validation or sanitization of retrieved content is documented.
Audit Metadata