gleam-testing
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as 'gleam test' and 'gleam deps download' to run test suites and manage project dependencies.
- [EXTERNAL_DOWNLOADS]: The skill references multiple external documentation sources and Gleam packages, including hexdocs.pm, tour.gleam.run, and community-maintained tutorials.
- [PROMPT_INJECTION]: Indirect prompt injection surface identified: 1. Ingestion points: External documentation links in SKILL.md (e.g., hexdocs.pm, gearsco.de, abs0luty.github.io). 2. Boundary markers: The skill does not provide delimiters or instructions to ignore embedded prompts in external content. 3. Capability inventory: The agent is instructed to use shell execution tools ('gleam test', 'gleam deps') to manage the local project environment. 4. Sanitization: There is no validation or sanitization process defined for the external documentation content ingested by the agent.
Audit Metadata