summarize
Pass
Audited by Gen Agent Trust Hub on Mar 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
summarizeutility via a third-party Homebrew tap (steipete/tap/summarize). - [COMMAND_EXECUTION]: The skill instructs the agent to execute the
summarizecommand-line tool with user-provided URLs and file paths. - [PROMPT_INJECTION]: The skill processes untrusted external content (URLs, YouTube transcripts, and local files), creating an indirect prompt injection surface. Ingestion points: External URLs, YouTube video links, and local file paths. Boundary markers: No explicit instructions are provided for the agent to use delimiters or boundary markers to isolate untrusted content. Capability inventory: The skill uses the
summarizebinary for content extraction. Sanitization: The skill definition does not specify any sanitization or validation of the ingested external content.
Audit Metadata