picking-a-format
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes how to use the
xbergtool to extract content from external files (e.g., PDFs). This creates an attack surface where an agent could ingest untrusted data containing malicious instructions. However, the skill itself provides only documentation for the extraction tool and does not provide mechanisms for automated execution of ingested content. - [COMMAND_EXECUTION]: The skill provides examples of shell commands using the
xbergCLI tool andjq. These are standard command-line utility examples related to the skill's primary purpose of document extraction and formatting. - [METADATA_POISONING]: The skill includes blake3 content and source hashes in the comments. These are integrity markers and do not contain malicious instructions or deceptive metadata.
Audit Metadata