explain
Pass
Audited by Gen Agent Trust Hub on Feb 25, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
mthds-agentCLI tool to validate and run bundles. This tool is a vendor resource belonging to 'mthds-ai' and is used as intended for the skill's primary functionality.\n- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it reads and interprets.mthdsbundle files which are untrusted external data sources.\n - Ingestion points:
.mthdsbundle files (Step 1).\n - Boundary markers: No boundary markers or instructions to ignore embedded commands are present in the skill definition.\n
- Capability inventory: The skill can execute shell commands via
mthds-agent pipelex validate(Step 6) andmthds-agent pipelex run pipe(Step 7).\n - Sanitization: There is no evidence of sanitization or content validation before the data is processed for explanation.
Audit Metadata