record-terminal
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill launches a terminal emulator (
ttyd) that provides a real shell (/bin/zsh) accessible via a local browser session. Security is maintained by binding the service to the local loopback interface (127.0.0.1orlo0) and using the-o(once) flag to prevent unauthorized or multiple connections.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes command sequences that may be sourced from untrusted data, creating a potential surface for injection.\n - Ingestion points: The "command sequence" mentioned in the preparation steps (SKILL.md).\n
- Boundary markers: None identified; instructions do not specify delimiters to isolate the command data from the prompt.\n
- Capability inventory: Interactive shell access via
ttydand control of a Chrome browser window.\n - Sanitization: No validation or sanitization of the input commands is performed before they are executed in the shell.\n- [EXTERNAL_DOWNLOADS]: The skill suggests installing
ttydusing Homebrew or system package managers. These are trusted, well-known services for package distribution.
Audit Metadata