publish-zsxq-article
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- Category 8: Indirect Prompt Injection (SAFE): While the script ingests untrusted data (HTML content from CLI arguments or files), it only writes this data to the system clipboard. It does not execute the data as code nor does it process it in a way that would influence the agent's logic or internal state. Any risk associated with pasting the resulting clipboard content is external to the script itself.
- Ingestion points: The script reads from
sys.stdin, file paths via--file, and direct CLI arguments inscripts/copy_to_clipboard.py. - Boundary markers: None (typical for clipboard utilities).
- Capability inventory: File system read access and system clipboard write access (
AppKiton macOS,win32clipboardandclip-utilon Windows). - Sanitization: None; the HTML is passed directly to the clipboard as intended for rich-text support.
Audit Metadata