ask
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability surface through the ingestion of untrusted data.
- Ingestion points: The
{{ARGUMENTS}}placeholder inSKILL.mdingests arbitrary user text. - Boundary markers: Absent; no delimiters isolate the user input from the rest of the prompt context.
- Capability inventory: The skill triggers shell execution via the
omc askcommand. - Sanitization: Absent; no input cleaning or escaping mechanisms are described.
- [COMMAND_EXECUTION]: User-supplied text is interpolated directly into the shell command template
omc ask {{ARGUMENTS}}, which could allow command injection if arguments are not safely handled by the agent platform. - [EXTERNAL_DOWNLOADS]: The documentation guides the installation of the
agybinary from the official Google domainhttps://antigravity.google.
Audit Metadata