skills/posit-dev/skills/r-cli/Gen Agent Trust Hub

r-cli

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The documentation describes the .run inline markup class, which enables the execution of R code when a user interacts with the message in supported IDEs like RStudio. The skill correctly identifies this as a sensitive feature and provides clear security warnings, advising users to never use it with untrusted input or for operations involving network access or file system modifications.
  • [DYNAMIC_EXECUTION]: The skill covers the package's theming system, which allows for dynamic text transformation and formatting using custom R functions defined in the fmt or transform properties. These functions are executed during the message rendering process.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents an attack surface where untrusted data could be interpolated into CLI messages. 1. Ingestion points: Variables are interpolated into strings via cli_text() and related functions in SKILL.md and references/conditions.md. 2. Boundary markers: The skill explains the use of {} for interpolation and {{}} for escaping literal braces in SKILL.md. 3. Capability inventory: The cli functions can trigger code execution via documented features like .run markup and theme functions. 4. Sanitization: The documentation explicitly warns against passing user-supplied input into dangerous markup classes in references/ansi-operations.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 09:00 PM