gcc
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential indirect prompt injection surface through workspace files.
- Ingestion points:
scripts/gcc_project.py,scripts/gcc_build.py, andscripts/gcc_size.pyread and parse untrusted local project files, includingCMakeLists.txt,CMakePresets.json, linker scripts, and compiler build log outputs. - Boundary markers: The extracted information (such as project names, presets, and build errors) is added directly into JSON response objects without prompt delimiters or specialized boundary markers.
- Capability inventory: The skill possesses extensive system interaction capabilities, including compiling binaries and invoking external developer utilities.
- Sanitization: No data validation or sanitization is executed on the parsed workspace text to prevent embedded LLM instructions from influencing the agent pipeline.
- [COMMAND_EXECUTION]: Local process execution occurs across several scripts.
- Evidence:
scripts/gcc_build.pyandscripts/gcc_size.pyexecutecmake,taskkill, and toolchain size binaries viasubprocess.runandsubprocess.Popencalls. - Context: This behavior is safe and aligned with the primary purpose of an embedded compilation utility. Commands are structured safely using lists/arrays instead of raw shell command strings, neutralizing typical shell command injection paths.
Audit Metadata