skills/vesely/skills/tldr/Gen Agent Trust Hub

tldr

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted conversation history and pull request data to generate summaries and suggest next steps.\n
  • Ingestion points: Conversation threads, PR URLs, and PR descriptions are processed as primary inputs for the summarization logic as defined in the Scope section of SKILL.md.\n
  • Boundary markers: The instructions do not define clear delimiters or instruct the agent to ignore potentially malicious embedded instructions within the summarized content.\n
  • Capability inventory: The agent has access to write to the scratchpad directory and execute shell commands (bash) to generate visual previews as described in the Variant section.\n
  • Sanitization: There is no explicit sanitization or validation step for the external content before it is used to generate actionable labels or shell scripts.\n- [COMMAND_EXECUTION]: The instructions for the visual preview variant direct the agent to use shell commands (e.g., bash with heredocs and base64) to construct temporary markdown files for display. While these are intended for legitimate utility, they create a surface where untrusted data from the thread might influence the shell interaction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:21 PM
Security Audit — agent-trust-hub — tldr