explore

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The troubleshooting section instructs the agent to install the llm-tldr package from external registries using uv or pip. This introduces a dependency on third-party code that is not pinned or verified within the skill's own manifest.
  • [DYNAMIC_EXECUTION]: The skill dynamically constructs shell commands by interpolating user-supplied variables such as FOCUS, ENTRY, and PATH (e.g., tldr search "${FOCUS}"). This pattern is susceptible to command injection if the input strings contain shell metacharacters and are not properly sanitized by the execution environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze untrusted codebase content, creating a significant attack surface for indirect prompt injection. Malicious instructions embedded in the code being explored could potentially influence the agent's behavior.
  • Ingestion points: Codebase files and directory structures accessed via Read, Grep, Glob, and various tldr utility commands.
  • Boundary markers: The skill does not define specific delimiters or warnings to treat ingested code content as untrusted data.
  • Capability inventory: The agent has access to powerful tools including Bash, Write, and Task (for spawning sub-agents), which increases the potential impact of a successful injection.
  • Sanitization: There is no explicit logic for sanitizing or escaping content retrieved from the codebase before it is processed or summarized by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 01:59 AM
Security Audit — agent-trust-hub — explore