haskell-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references standard package management tools like
cabalandstackto download dependencies from the Haskell package repository Hackage. - [REMOTE_CODE_EXECUTION]: The documentation provides examples for installing the GHCup and Stack toolchains using
curlpiped toshfromget-ghcup.haskell.organdget.haskellstack.org. These are the official and standard installation vectors for the Haskell ecosystem. - [COMMAND_EXECUTION]: Includes instructions for executing shell commands for project initialization, compilation, and dependency management using
ghcup,cabal, andstackwithin aBashenvironment. - [INDIRECT_PROMPT_INJECTION]: The skill defines a surface where untrusted user-provided code could potentially influence the agent's actions due to its broad capabilities.
- Ingestion points: Haskell code snippets and programming queries processed by the agent (identified in
SKILL.md). - Boundary markers: The instructions do not define strict delimiters or warnings to ignore instructions embedded in the code being analyzed.
- Capability inventory: The skill environment allows for
Bashexecution and file modification (Write,Edit) alongsideReadoperations. - Sanitization: There are no documented mechanisms for sanitizing or isolating untrusted external code before processing.
Audit Metadata