skills/wot-ui/open-wot/wot-ui-cli/Gen Agent Trust Hub

wot-ui-cli

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute various shell commands for repository development, build, and testing as seen in SKILL.md and references/overview.md. Examples include pnpm install, pnpm build, pnpm test, node dist/index.mjs, and pnpm exec tsx src/index.ts. These commands are standard for a Node.js development environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides tools for project analysis that ingest untrusted data from local directories, creating a potential vector for indirect prompt injection. (1) Ingestion points: Tools described in SKILL.md and references/overview.md (e.g., wot doctor, wot usage, wot lint) scan project directories ([dir]) and read source files (e.g., .vue files). (2) Boundary markers: There are no markers or 'ignore' instructions defined in SKILL.md to prevent the agent from following instructions found within the processed files. (3) Capability inventory: As detailed in SKILL.md and references/overview.md, the skill can execute shell commands (pnpm, node, tsx), write configuration files (e.g., .cursor/mcp.json, opencode.json), and perform data synchronization/extraction. (4) Sanitization: The skill instructions do not specify any sanitization or validation of the data extracted from project files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:06 AM
Security Audit — agent-trust-hub — wot-ui-cli