tldr-router
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input (questions) to determine tool routing and command arguments.
- Ingestion points: User messages used to extract parameters such as
<function>,<file>, and<line>in SKILL.md. - Boundary markers: None identified; the skill does not instruct the agent to ignore or delimit embedded instructions in the user's input.
- Capability inventory: The skill triggers
tldrcommands with subcommands for file system traversal (tree), structural search (search), and static analysis (cfg,dfg,slice). - Sanitization: No explicit instructions are provided to sanitize or validate user-provided identifiers before they are interpolated into executable shell commands.
- [COMMAND_EXECUTION]: The skill suggests constructing shell commands using variables directly from user queries (e.g.,
tldr cfg <file> <function>). This creates a command injection risk if the agent's execution environment fails to escape special characters or shell metacharacters provided in the user's input.
Audit Metadata