utility-pro

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill provides patterns for processing untrusted data from external sources without explicit security boundaries.\n
  • Ingestion points: API interaction via xh and Nushell http get in SKILL.md and references/3-nushell-structured-data.md.\n
  • Boundary markers: Absent; no instructions are provided to wrap external content in delimiters.\n
  • Capability inventory: File modification using sed -i and command execution via fd -x.\n
  • Sanitization: Absent; no validation or filtering of external data is mentioned before it is processed by powerful CLI tools.\n- [Command Execution] (SAFE): CLI tools like sed and fd are used for legitimate system utility tasks as described in the skill documentation.\n- [External Downloads] (LOW): Network interaction targets api.squaads.com and api.github.com, which are not included in the specific trusted domain whitelist for exfiltration analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:17 PM