oss-alternatives
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on the
tinyfishCLI to perform web searches and repository health checks. It also utilizes standard shell utilities such ascat,wait, andechofor managing temporary JSON results stored in/tmp/. - [EXTERNAL_DOWNLOADS]: The skill references and fetches data from established external platforms including GitHub and Reddit to evaluate software alternatives. These operations are part of the skill's primary function to aggregate public project metadata.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external web sources, which is a potential vector for indirect prompt injection. The skill mitigates this risk by providing specific instructions to the extraction agents to limit their scope and by advising that all external content be treated as untrusted for synthesis only.
- Ingestion points: Web content retrieved from GitHub search, curated repository lists, and Reddit discussion threads (SKILL.md).
- Boundary markers: The skill uses environment descriptions and specific output format requirements (JSON) for the extraction agents.
- Capability inventory: Execution of
tinyfishfor web access and repository analysis; shell operations for file management. - Sanitization: Content is marked as untrusted and intended for synthesis by the LLM without further execution.
Audit Metadata