tldr-overview
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands using the
tldrutility for mapping file structures, identifying code components, and building architecture call graphs. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local project files, creating a vulnerability to embedded instructions.
- Ingestion points: Project file tree and code structure are read into the agent context via
tldr tree,tldr structure, andtldr calls. - Boundary markers: The skill does not implement delimiters or safety instructions to distinguish code content from potential commands.
- Capability inventory: The skill is capable of performing deep structural analysis and metadata extraction from local files.
- Sanitization: There is no evidence of content filtering or validation for the ingested project data.
Audit Metadata