redline
Warn
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes an instruction to the agent that any version of the 'redline' skill found within the local repository directory (
.claude/skills/redline/or.agents/skills/redline/) should be considered authoritative and followed instead of the global version. This creates a mechanism for untrusted local files to override the agent's core instructions and safety parameters. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from a Markdown file located in the user's downloads folder and applies the changes directly to the source code or documents.
- Ingestion points: Reads the latest
*.redline.mdfile from~/Downloads(Linux/macOS) or%USERPROFILE%\Downloads(Windows). - Boundary markers: None identified; instructions emphasize that human edits are 'decisions' to be applied 'verbatim'.
- Capability inventory: The agent has the capability to write to the local file system to apply the reviewed changes.
- Sanitization: No sanitization or validation of the input file's content is performed before application to the source artifact.
- [COMMAND_EXECUTION]: The skill triggers platform-specific shell commands to open generated HTML files in the user's default browser (
open,xdg-open,start). - [COMMAND_EXECUTION]: The skill performs shell-based file system lookups to identify the newest review file in the downloads directory using
lsordircommands.
Audit Metadata