redline

Warn

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes an instruction to the agent that any version of the 'redline' skill found within the local repository directory (.claude/skills/redline/ or .agents/skills/redline/) should be considered authoritative and followed instead of the global version. This creates a mechanism for untrusted local files to override the agent's core instructions and safety parameters.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from a Markdown file located in the user's downloads folder and applies the changes directly to the source code or documents.
  • Ingestion points: Reads the latest *.redline.md file from ~/Downloads (Linux/macOS) or %USERPROFILE%\Downloads (Windows).
  • Boundary markers: None identified; instructions emphasize that human edits are 'decisions' to be applied 'verbatim'.
  • Capability inventory: The agent has the capability to write to the local file system to apply the reviewed changes.
  • Sanitization: No sanitization or validation of the input file's content is performed before application to the source artifact.
  • [COMMAND_EXECUTION]: The skill triggers platform-specific shell commands to open generated HTML files in the user's default browser (open, xdg-open, start).
  • [COMMAND_EXECUTION]: The skill performs shell-based file system lookups to identify the newest review file in the downloads directory using ls or dir commands.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 24, 2026, 11:18 PM
Security Audit — agent-trust-hub — redline