skills/withqwerty/nutmeg/nutmeg-heal/Gen Agent Trust Hub

nutmeg-heal

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves retrieving and analyzing untrusted data from the web, which creates a potential surface for indirect prompt injection attacks. * Ingestion points: The skill uses WebFetch and WebSearch tools to obtain content from external APIs and websites (SKILL.md). * Boundary markers: Absent. There are no specific delimiters defined to separate untrusted data from agent instructions in the prompt logic. * Capability inventory: The skill is permitted to use Bash for command execution and Write for file modifications (SKILL.md). * Sanitization: Present. The instructions include a Security section that explicitly warns the agent to treat external content as untrusted, validate schemas, and avoid executing code found in fetched data.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform diagnostics on local code and verify library versions. * This capability is used to identify environment-specific errors and verify fixes, which is consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 03:24 PM
Security Audit — agent-trust-hub — nutmeg-heal