nutmeg-store
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to read a user-controlled profile file (
.nutmeg.user.md) to tailor its data storage and publishing recommendations based on the user's goals and technical level. This creates a surface where malicious instructions inside the profile could influence the agent's behavior. - Ingestion points: The agent reads the
.nutmeg.user.mdfile at the start of the interaction. - Boundary markers: There are no explicit delimiters or instructions to treat the file content as untrusted data.
- Capability inventory: The skill is configured with powerful tools including
Bash,Write, andReadcapabilities. - Sanitization: No sanitization or validation logic is defined for the content retrieved from the user profile.
Audit Metadata