wot-ui-cli
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute various shell commands for repository development, build, and testing as seen in SKILL.md and references/overview.md. Examples include pnpm install, pnpm build, pnpm test, node dist/index.mjs, and pnpm exec tsx src/index.ts. These commands are standard for a Node.js development environment.
- [INDIRECT_PROMPT_INJECTION]: The skill provides tools for project analysis that ingest untrusted data from local directories, creating a potential vector for indirect prompt injection. (1) Ingestion points: Tools described in SKILL.md and references/overview.md (e.g., wot doctor, wot usage, wot lint) scan project directories ([dir]) and read source files (e.g., .vue files). (2) Boundary markers: There are no markers or 'ignore' instructions defined in SKILL.md to prevent the agent from following instructions found within the processed files. (3) Capability inventory: As detailed in SKILL.md and references/overview.md, the skill can execute shell commands (pnpm, node, tsx), write configuration files (e.g., .cursor/mcp.json, opencode.json), and perform data synchronization/extraction. (4) Sanitization: The skill instructions do not specify any sanitization or validation of the data extracted from project files before it is processed by the agent.
Audit Metadata