skill
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill scans and parses metadata from markdown files located within project directories (
.omc/skills/). This creates a vector where a malicious actor could influence the agent's behavior by placing a specially crafted markdown file in a shared project repository. The agent would then ingest and display the 'name', 'description', and 'triggers' from these files during list or scan operations. - Ingestion points: Processes all
.mdfiles in project and user skill directories within the/skill setupand/skill scancommands inSKILL.md. - Boundary markers: The inventory display logic lacks explicit delimiters or instructions to ignore embedded prompts within the metadata of scanned skills.
- Capability inventory: File system modification (
mkdir,rm), file writing (write), shell command execution (find,grep,sed), and network interaction (implied by the import feature). - Sanitization: The skill extracts metadata using
grepandsedand displays it directly in a table format without performing validation or escaping of the content. - [EXTERNAL_DOWNLOADS]: The skill includes an 'Import skill' option that allows the agent to download skill content from an arbitrary user-provided URL. This download capability allows the agent to fetch and save external code/instructions into its local skill directories. If a user provides a malicious URL, this could result in the installation of unsafe agent skills.
- [COMMAND_EXECUTION]: To generate its skill inventory, the skill executes complex shell command pipelines including
find,grep,sed, andstatviash -c. While the implementation correctly passes filenames as arguments to avoid basic command injection via filenames, it represents a direct interaction with the host system's shell environment.
Audit Metadata