haskell-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references standard package management tools like cabal and stack to download dependencies from the Haskell package repository Hackage.
  • [REMOTE_CODE_EXECUTION]: The documentation provides examples for installing the GHCup and Stack toolchains using curl piped to sh from get-ghcup.haskell.org and get.haskellstack.org. These are the official and standard installation vectors for the Haskell ecosystem.
  • [COMMAND_EXECUTION]: Includes instructions for executing shell commands for project initialization, compilation, and dependency management using ghcup, cabal, and stack within a Bash environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface where untrusted user-provided code could potentially influence the agent's actions due to its broad capabilities.
  • Ingestion points: Haskell code snippets and programming queries processed by the agent (identified in SKILL.md).
  • Boundary markers: The instructions do not define strict delimiters or warnings to ignore instructions embedded in the code being analyzed.
  • Capability inventory: The skill environment allows for Bash execution and file modification (Write, Edit) alongside Read operations.
  • Sanitization: There are no documented mechanisms for sanitizing or isolating untrusted external code before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — haskell-expert