interview-cheatsheet
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
python3to execute a local scriptskills/render-html/scripts/render_html.py. This script is part of the internal toolchain for rendering generated markdown into HTML and is invoked with controlled arguments based on the tutorial's metadata. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided topics to generate large-scale markdown files which are then analyzed by a separate LLM (
mcp__codex__codex). This ingestion of untrusted user data into a multi-step pipeline is an attack surface, but is mitigated by the following: - Ingestion points: User-provided
<topic>and the resulting draft markdown file. - Boundary markers: The instructions do not specify delimiters for the drafted content passed to the reviewer, though the reviewer is constrained by a strict checklist.
- Capability inventory: The agent possesses file system access (Read, Write, Edit) and shell execution capabilities.
- Sanitization: The skill employs a secondary model review and includes a specific PII detection banlist to filter content before completion.
Audit Metadata