summarize

Warn

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of a third-party binary (summarize) from a non-trusted Homebrew repository (steipete/tap/summarize).
  • [COMMAND_EXECUTION]: The skill operates by executing shell commands using the summarize binary, passing user-controlled data such as URLs and file paths as arguments to the command.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it is designed to ingest and process untrusted data from external URLs (including YouTube transcripts and articles) and local files.
  • Ingestion points: URLs, YouTube links, and local file paths (specified in SKILL.md).
  • Boundary markers: None explicitly defined in the instructions to prevent the agent from obeying instructions embedded within the content being summarized.
  • Capability inventory: The skill can execute shell commands, read local files, and perform network operations to fetch external content.
  • Sanitization: There are no documented sanitization or filtering mechanisms for the external content processed by the tool.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 19, 2026, 06:32 AM
Security Audit — agent-trust-hub — summarize