skills/theorcdev/skills/cut-it/Gen Agent Trust Hub

cut-it

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as GitHub issues, PRDs, and documentation files to generate execution plans.\n- Ingestion points: The instructions in SKILL.md (Step 1) direct the agent to read from conversation history, local files (e.g., PLAN.md), GitHub issues, and PRD documents.\n- Boundary markers: No specific delimiters or instructions are provided to help the agent differentiate between data and instructions within the source materials.\n- Capability inventory: The tool generates executable steps including concrete shell commands and file modifications for subsequent agent action.\n- Sanitization: The skill lacks explicit validation or sanitization steps to filter potential malicious payloads from external source documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:29 PM
Security Audit — agent-trust-hub — cut-it