sandbox-agent
Audited by ZeroLeaks on Apr 15, 2026
The skill's SKILL.md is mostly clear, but carries one notable transparency concern: it references remote script execution without establishing a review boundary, which weakens the ability to fully audit what the agent will actually run. Instruction/data separation looks reasonable, and the scan did not surface strong prompt-injection vectors. However, behavior analysis was not run, so it's not possible to confirm whether loading this skill materially changes downstream behavior compared to a no-skill baseline—this gap, combined with the unreviewed remote execution path, supports the AT_RISK verdict. Confidence is medium because finite testing passed on injection risk, but the missing behavior analysis and the opaque remote execution leave meaningful uncertainty unresolved.
The skill has 1 transparency concern that weaken pre-use reviewability, mainly around remote script execution without review boundary.
The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.
Behavior analysis was not run.
Remote script execution without review boundary