r-cli
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The documentation describes the
.runinline markup class, which enables the execution of R code when a user interacts with the message in supported IDEs like RStudio. The skill correctly identifies this as a sensitive feature and provides clear security warnings, advising users to never use it with untrusted input or for operations involving network access or file system modifications. - [DYNAMIC_EXECUTION]: The skill covers the package's theming system, which allows for dynamic text transformation and formatting using custom R functions defined in the
fmtortransformproperties. These functions are executed during the message rendering process. - [INDIRECT_PROMPT_INJECTION]: The skill documents an attack surface where untrusted data could be interpolated into CLI messages. 1. Ingestion points: Variables are interpolated into strings via
cli_text()and related functions inSKILL.mdandreferences/conditions.md. 2. Boundary markers: The skill explains the use of{}for interpolation and{{}}for escaping literal braces inSKILL.md. 3. Capability inventory: Theclifunctions can trigger code execution via documented features like.runmarkup and theme functions. 4. Sanitization: The documentation explicitly warns against passing user-supplied input into dangerous markup classes inreferences/ansi-operations.md.
Audit Metadata