nia-docs
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Python script (
scripts/mcp/nia_docs.py) usinguv runand shell commands to perform documentation searches. - [INDIRECT_PROMPT_INJECTION]: The skill defines a vulnerability surface where untrusted user input is ingested and passed directly into a shell execution environment.
- Ingestion points: User-provided search queries, package names, and regex patterns passed to the
--query,--search, and--grepflags inSKILL.md. - Boundary markers: The usage examples do not include delimiters or specific instructions to the agent to sanitize or ignore embedded instructions within the user-provided query strings.
- Capability inventory: The skill utilizes shell execution (Bash) and file reading capabilities.
- Sanitization: There is no explicit sanitization or escaping of user-provided strings before they are interpolated into the shell command, which could lead to command injection if a user provides a malicious payload.
Audit Metadata