skills/jr2804/prompts/cli-cytoscnpy/Gen Agent Trust Hub

cli-cytoscnpy

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface exists because the tool processes external Python files. Malicious content within source files could theoretically influence the agent's reasoning if embedded in comments or strings. * Ingestion points: File paths passed to metrics commands in SKILL.md and cli-reference.md. * Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded content in the tool's output. * Capability inventory: The skill utilizes the CLI for reading files and reporting statistics. * Sanitization: No input validation or sanitization of the source code is mentioned.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands through the cytoscnpy CLI. This includes filesystem modification via the cytoscnpy init command, which creates or updates configuration files such as .cytoscnpy.toml in the current directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 07:20 AM