share-field-notes
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the
universal-moddertool suite directly from the author's GitHub repository (github.com/rehan-remade/universal-modder) using theuvtool manager.- [COMMAND_EXECUTION]: The skill utilizes a custom command-line interface (um) to perform operations such as searching, displaying, and managing knowledge base entries, including the automated generation of pull requests.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to retrieve and process community-contributed modding notes, which could contain malicious instructions or biased information from untrusted third parties. - Ingestion points: External content is retrieved and displayed via
um kb searchandum kb showcommands in SKILL.md. - Boundary markers: The instructions include a safety warning advising the agent to treat ingested notes as hints rather than authoritative sources and to avoid running commands found within them blindly.
- Capability inventory: The agent is empowered to write to the file system, execute the
umtool (which interacts with Git), and submit data to a public repository via pull requests. - Sanitization: The
um kb checkutility is intended to identify and block the inclusion of secrets or malformed content in contributions, providing a basic level of outgoing data validation.
Audit Metadata