tldr-router

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input (questions) to determine tool routing and command arguments.
  • Ingestion points: User messages used to extract parameters such as <function>, <file>, and <line> in SKILL.md.
  • Boundary markers: None identified; the skill does not instruct the agent to ignore or delimit embedded instructions in the user's input.
  • Capability inventory: The skill triggers tldr commands with subcommands for file system traversal (tree), structural search (search), and static analysis (cfg, dfg, slice).
  • Sanitization: No explicit instructions are provided to sanitize or validate user-provided identifiers before they are interpolated into executable shell commands.
  • [COMMAND_EXECUTION]: The skill suggests constructing shell commands using variables directly from user queries (e.g., tldr cfg <file> <function>). This creates a command injection risk if the agent's execution environment fails to escape special characters or shell metacharacters provided in the user's input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — tldr-router