halo-operations
Pass
Audited by Gen Agent Trust Hub on Mar 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Provides instructions for executing site management tasks using the
haloCLI tool, including installation and deletion of themes and plugins.- [EXTERNAL_DOWNLOADS]: Facilitates fetching and installing themes, plugins, and attachments from remote URLs using command flags like--url.- [PROMPT_INJECTION]: Potential for indirect prompt injection if the agent is directed to process untrusted external URLs for site configuration or content management. Evidence: 1. Ingestion points: URL flags inhalo theme install,halo plugin install, andhalo attachment uploadinSKILL.md. 2. Boundary markers: None. 3. Capability inventory:haloCLI execution for file system and site modification. 4. Sanitization: None.
Audit Metadata