second-opinion

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it interpolates untrusted document content directly into a prompt for another LLM.
  • Ingestion points: Document content and optional skill files (SKILL.md) are read in Step 2 of SKILL.md.
  • Boundary markers: Absent. The prompt template does not use specific delimiters or instructions to ignore embedded commands within the processed document.
  • Capability inventory: The skill utilizes subprocess calls (cat, mkdir), file writes, and network operations via the gemini CLI tool in SKILL.md.
  • Sanitization: Absent. The content is directly substituted into the prompt string.
  • [DATA_EXFILTRATION]: Local document content and referenced skill files are transmitted to an external service (Gemini) for analysis.
  • [COMMAND_EXECUTION]: The skill uses shell redirection and pipes (cat > /tmp/second-opinion-prompt.md) to create temporary files and execute the gemini CLI tool with substituted content.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 11:34 AM