skills/renatillas/gleam/gleam-testing/Gen Agent Trust Hub

gleam-testing

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as 'gleam test' and 'gleam deps download' to run test suites and manage project dependencies.
  • [EXTERNAL_DOWNLOADS]: The skill references multiple external documentation sources and Gleam packages, including hexdocs.pm, tour.gleam.run, and community-maintained tutorials.
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified: 1. Ingestion points: External documentation links in SKILL.md (e.g., hexdocs.pm, gearsco.de, abs0luty.github.io). 2. Boundary markers: The skill does not provide delimiters or instructions to ignore embedded prompts in external content. 3. Capability inventory: The agent is instructed to use shell execution tools ('gleam test', 'gleam deps') to manage the local project environment. 4. Sanitization: There is no validation or sanitization process defined for the external documentation content ingested by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 05:27 PM
Security Audit — agent-trust-hub — gleam-testing