write-alt-text

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides specific shell commands using grep to search for figure labels and line numbers within local Quarto markdown (.qmd) files.
  • [PROMPT_INJECTION]: The skill processes untrusted data from local project files, which introduces a surface for indirect prompt injection. * Ingestion points: Reads .qmd files located in the project directory via grep and direct file access. * Boundary markers: None specified; the agent is instructed to read raw code and prose around detected chunks. * Capability inventory: Shell access and file system read access. * Sanitization: No explicit sanitization or content validation is implemented for the ingested file data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 08:06 AM