tldr-overview

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands using the tldr utility for mapping file structures, identifying code components, and building architecture call graphs.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local project files, creating a vulnerability to embedded instructions.
  • Ingestion points: Project file tree and code structure are read into the agent context via tldr tree, tldr structure, and tldr calls.
  • Boundary markers: The skill does not implement delimiters or safety instructions to distinguish code content from potential commands.
  • Capability inventory: The skill is capable of performing deep structural analysis and metadata extraction from local files.
  • Sanitization: There is no evidence of content filtering or validation for the ingested project data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — tldr-overview