tldr-deep

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides templates for shell commands (e.g., tldr search "def <function_name>" .) that interpolate user-provided function names and line numbers directly into shell arguments. If the agent does not properly sanitize these inputs, it could lead to shell command injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze external source code, which constitutes untrusted data.
  • Ingestion points: Source code files within the project directory are read and summarized using the tldr suite of tools.
  • Boundary markers: The instructions do not specify any delimiters or instructions for the agent to ignore potentially malicious instructions embedded in code comments or strings during analysis.
  • Capability inventory: The skill possesses the ability to read arbitrary project files and execute shell commands for analysis.
  • Sanitization: There is no evidence of filtering or sanitizing the content of the files before they are processed by the LLM, making the agent susceptible to instructions hidden within the analyzed code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — tldr-deep