skills/vesely/skills/share-file/Gen Agent Trust Hub

share-file

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill uploads user-specified files to Cloudflare R2 storage. It uses the official wrangler command-line tool to communicate with Cloudflare's r2.dev infrastructure. As Cloudflare is a well-known service and the data transfer is the core documented purpose of the skill, this is considered a safe operational behavior.
  • [COMMAND_EXECUTION]: The script executes several shell utilities including wrangler, openssl, sed, tr, and file. These are used to manage bucket configurations, generate unique filename slugs, and detect file mime-types to ensure proper browser rendering of shared links.
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to install the wrangler package via npm. This is a standard installation of a well-known development tool from a reputable registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes local files which serve as an ingestion point for untrusted data. While the script performs no sanitization or instruction filtering on the file content, its capabilities are restricted to file movement. The potential risk involves an agent being influenced by instructions contained within a file it is asked to share, but the skill itself acts only as a passive hosting utility.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:21 PM
Security Audit — agent-trust-hub — share-file