secrets-in-file-metadata

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional, teaching the use of standard, well-known forensic utilities (exiftool, unzip, pdfimages, qpdf, magick) for metadata analysis. All provided command-line examples are read-only or local operations designed for investigation.
  • [DATA_EXPOSURE]: The skill correctly identifies and highlights the risks of sensitive data exposure (GPS, internal network paths, user identities) within file metadata. It explicitly warns against uploading evidence to online third-party metadata viewers to prevent data exfiltration.
  • [PROMPT_INJECTION]: The skill processes untrusted metadata from external files, which constitutes an indirect prompt injection surface. However, the instructions emphasize that metadata tags are merely 'claims' and should not be treated as authoritative proof, encouraging cross-verification with other evidence.
  • [COMMAND_EXECUTION]: The provided shell commands use standard tools for their intended purposes. The interpolation patterns (e.g., '$gpslatitude') are specific to exiftool's formatting syntax and do not introduce shell-level command injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 08:32 PM
Security Audit — agent-trust-hub — secrets-in-file-metadata