loogle-search

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute local commands including loogle-search, loogle-server, and the Lean build tool lake. These commands are executed against a local directory structure (~/tools/loogle).
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the processing of user-supplied search patterns (e.g., "Nontrivial _ ↔ _") that are passed directly as arguments to shell commands.
  • Ingestion points: Search patterns provided by the user in the proof or search context are ingested in SKILL.md examples.
  • Boundary markers: The instructions lack explicit boundary markers or warnings to the agent to treat search patterns as untrusted data.
  • Capability inventory: The skill uses loogle-search and loogle-server execution capabilities.
  • Sanitization: There is no mention of input validation or escaping for the search patterns before they are passed to the shell.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — loogle-search