deepvista-vistabook

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the deepvista CLI tool to perform various workflow management tasks, including listing templates, initiating runs, and checking execution status.
  • [EXTERNAL_DOWNLOADS]: The skill metadata specifies that it requires the uv binary and the deepvista-shared skill to be available in the execution environment.
  • [PROMPT_INJECTION]: The +run command accepts external context through the --input parameter. This creates a surface for indirect prompt injection if the agent populates this field with untrusted data (such as information from web searches or external files), which could potentially influence the agent's behavior during the workflow's execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 03:33 AM