tldr-router

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines and utilizes various shell commands through a 'tldr' utility for code analysis. These include tldr tree for file overviews, tldr cfg for control flow, tldr dfg for data flow, and tldr slice for impact analysis.
  • [PROMPT_INJECTION]: The skill operates as an intent-detection system that processes user messages to automatically trigger specific tool calls. This ingestion of untrusted natural language data to populate command arguments (such as function names and file paths) represents an indirect prompt injection surface. No explicit sanitization or boundary markers are defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 07:46 AM
Security Audit — agent-trust-hub — tldr-router