oc-thumbnail-designer

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from 'transcript.md' to generate headlines for thumbnails, creating a potential surface for instructions embedded in external files to influence the agent.
  • Ingestion points: 'transcript.md' referenced in SKILL.md.
  • Boundary markers: No specific delimiters or safety instructions are provided for handling transcript content.
  • Capability inventory: Execution of the 'oc' CLI tool via the 'Bash' tool.
  • Sanitization: There are no explicit instructions for sanitizing or escaping content extracted from transcripts before it is passed as command-line arguments to the 'oc' tool.
  • [COMMAND_EXECUTION]: The skill utilizes the 'Bash' tool to execute the 'oc' command-line utility for various tasks including image rendering, taste management, and project configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:34 PM
Security Audit — agent-trust-hub — oc-thumbnail-designer