spectrum
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
terminalprovider is designed to download a helper binary (tuichat) from the official vendor repository atgithub.com/photon-hq/tuichatupon its first execution to provide a TUI interface. - [COMMAND_EXECUTION]: The skill documentation describes the
terminalprovider spawning a subprocess to execute thetuichatbinary, which is used to render the chat interface locally. - [INDIRECT_PROMPT_INJECTION]: As the skill is designed to ingest and process messages from external platforms (iMessage, WhatsApp, etc.), there is an inherent surface for indirect prompt injection.
- Ingestion points: Incoming message streams are processed via
app.messagesingetting-started.mdandmessages.md. - Boundary markers: The provided code samples do not explicitly implement boundary markers, leaving this to the developer implementing the agent logic.
- Capability inventory: The skill provides capabilities for sending messages (
space.send), replying (message.reply), and accessing local files for attachments (content.md). - Sanitization: The skill provides architectural guidance in
best-practices.mdfor handling message pipelines, but developers are responsible for sanitizing content before passing it to downstream LLMs.
Audit Metadata