parallel-findall
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes entity data (names, descriptions, and URLs) retrieved from external sources via the
parallel-clitool. This creates a surface where an attacker could influence the agent's behavior by embedding instructions in the metadata of discovered entities. - Ingestion points: The skill reads output from
parallel-cli findall pollandentity-search(SKILL.md). - Boundary markers: The instructions do not define specific delimiters to separate untrusted entity data from the system prompt.
- Capability inventory: The skill has the ability to execute shell commands via
parallel-cli. - Sanitization: While the skill suggests filtering 'noise' based on URL shape and name echoing, it does not explicitly sanitize the content for embedded prompt instructions.
- [COMMAND_EXECUTION]: The skill heavily relies on executing the
parallel-clitool in a Bash environment. These commands are integral to the skill's functionality and are associated with the vendor's own infrastructure.
Audit Metadata