ask

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability surface through the ingestion of untrusted data.
  • Ingestion points: The {{ARGUMENTS}} placeholder in SKILL.md ingests arbitrary user text.
  • Boundary markers: Absent; no delimiters isolate the user input from the rest of the prompt context.
  • Capability inventory: The skill triggers shell execution via the omc ask command.
  • Sanitization: Absent; no input cleaning or escaping mechanisms are described.
  • [COMMAND_EXECUTION]: User-supplied text is interpolated directly into the shell command template omc ask {{ARGUMENTS}}, which could allow command injection if arguments are not safely handled by the agent platform.
  • [EXTERNAL_DOWNLOADS]: The documentation guides the installation of the agy binary from the official Google domain https://antigravity.google.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:34 PM
Security Audit — agent-trust-hub — ask