cue-lang
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the CUE CLI using
go install cuelang.org/go/cmd/cue@latest. This targets the official domain for the CUE project. - [COMMAND_EXECUTION]: The documentation includes several shell command examples for managing configuration, such as
cue eval,cue export, andcue vet. Additionally, a Julia code snippet demonstrates executing thecuebinary as a subprocess via backticks to capture output. - [INDIRECT_PROMPT_INJECTION]: The skill documents an attack surface for indirect prompt injection as it is designed to process external data files.
- Ingestion points: Reads and validates
data.yaml,schema.cue, andconfig.cue(SKILL.md). - Boundary markers: None present in the instructional examples.
- Capability inventory: The skill uses the
cueCLI for evaluation and export; the Julia bridge utilizes subprocess execution to read CUE data. - Sanitization: CUE is explicitly designed to be non-Turing complete, which provides inherent protection against termination issues and side effects during data evaluation.
Audit Metadata