record-terminal

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill launches a terminal emulator (ttyd) that provides a real shell (/bin/zsh) accessible via a local browser session. Security is maintained by binding the service to the local loopback interface (127.0.0.1 or lo0) and using the -o (once) flag to prevent unauthorized or multiple connections.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes command sequences that may be sourced from untrusted data, creating a potential surface for injection.\n
  • Ingestion points: The "command sequence" mentioned in the preparation steps (SKILL.md).\n
  • Boundary markers: None identified; instructions do not specify delimiters to isolate the command data from the prompt.\n
  • Capability inventory: Interactive shell access via ttyd and control of a Chrome browser window.\n
  • Sanitization: No validation or sanitization of the input commands is performed before they are executed in the shell.\n- [EXTERNAL_DOWNLOADS]: The skill suggests installing ttyd using Homebrew or system package managers. These are trusted, well-known services for package distribution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:47 PM
Security Audit — agent-trust-hub — record-terminal