skills/pippit-dev/cli/xyq-skill/Gen Agent Trust Hub

xyq-skill

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The script ensure-cli.js is designed to download and update the toolkit from the official @pippit-dev/cli package on npm, ensuring the latest features and security updates are present.
  • [REMOTE_CODE_EXECUTION]: During initial setup or updates, the skill executes a platform-specific installer script included within the vendor's npm package to prepare the binary environment.
  • [COMMAND_EXECUTION]: The skill manages media tasks by executing local commands via the pippit-tool-cli binary and Node.js runtime, which are required for generative image and video processing.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge for user-supplied prompts to be processed by generative models, creating a potential surface for instructions embedded in data.
  • Ingestion points: User-provided creative prompts and local media file paths processed in the image and video generation modules.
  • Boundary markers: The skill uses structured CLI flags (e.g., --prompt) to delimit user content from command logic.
  • Capability inventory: The skill possesses file system access for media processing and cache management, network access for media uploading and status checks, and command execution capabilities.
  • Sanitization: Instructions explicitly forbid the agent from modifying or expanding the user's prompt, relying on the underlying service's internal validation for safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:12 PM