second-opinion
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it interpolates untrusted document content directly into a prompt for another LLM.
- Ingestion points: Document content and optional skill files (SKILL.md) are read in Step 2 of
SKILL.md. - Boundary markers: Absent. The prompt template does not use specific delimiters or instructions to ignore embedded commands within the processed document.
- Capability inventory: The skill utilizes subprocess calls (
cat,mkdir), file writes, and network operations via thegeminiCLI tool inSKILL.md. - Sanitization: Absent. The content is directly substituted into the prompt string.
- [DATA_EXFILTRATION]: Local document content and referenced skill files are transmitted to an external service (Gemini) for analysis.
- [COMMAND_EXECUTION]: The skill uses shell redirection and pipes (
cat > /tmp/second-opinion-prompt.md) to create temporary files and execute thegeminiCLI tool with substituted content.
Audit Metadata