skills/zhinkgit/embeddedskills/gcc/Gen Agent Trust Hub

gcc

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential indirect prompt injection surface through workspace files.
  • Ingestion points: scripts/gcc_project.py, scripts/gcc_build.py, and scripts/gcc_size.py read and parse untrusted local project files, including CMakeLists.txt, CMakePresets.json, linker scripts, and compiler build log outputs.
  • Boundary markers: The extracted information (such as project names, presets, and build errors) is added directly into JSON response objects without prompt delimiters or specialized boundary markers.
  • Capability inventory: The skill possesses extensive system interaction capabilities, including compiling binaries and invoking external developer utilities.
  • Sanitization: No data validation or sanitization is executed on the parsed workspace text to prevent embedded LLM instructions from influencing the agent pipeline.
  • [COMMAND_EXECUTION]: Local process execution occurs across several scripts.
  • Evidence: scripts/gcc_build.py and scripts/gcc_size.py execute cmake, taskkill, and toolchain size binaries via subprocess.run and subprocess.Popen calls.
  • Context: This behavior is safe and aligned with the primary purpose of an embedded compilation utility. Commands are structured safely using lists/arrays instead of raw shell command strings, neutralizing typical shell command injection paths.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:14 AM
Security Audit — agent-trust-hub — gcc