debug-php-wasm-side-modules
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides several shell commands and Node.js diagnostic scripts meant to be executed on files within the user's workspace (e.g., extension.so). If these filenames or the content within them are manipulated, they could potentially lead to command injection as no sanitization or boundary markers are suggested for the agent.\n
- Ingestion points: Workspace filenames and paths passed to wasm-objdump, wasm-opt, find, and the node -e scripts found in SKILL.md.\n
- Boundary markers: Absent. There are no instructions or warnings provided to the agent to validate or delimit these inputs before execution.\n
- Capability inventory: The skill leverages shell command execution (wasm-objdump, wasm-opt, find) and Node.js script execution (node -e).\n
- Sanitization: Absent. The diagnostic commands directly interpolate filenames into shell/Node.js strings.
Audit Metadata