utility-pro
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill provides patterns for processing untrusted data from external sources without explicit security boundaries.\n
- Ingestion points: API interaction via
xhand Nushellhttp getinSKILL.mdandreferences/3-nushell-structured-data.md.\n - Boundary markers: Absent; no instructions are provided to wrap external content in delimiters.\n
- Capability inventory: File modification using
sed -iand command execution viafd -x.\n - Sanitization: Absent; no validation or filtering of external data is mentioned before it is processed by powerful CLI tools.\n- [Command Execution] (SAFE): CLI tools like
sedandfdare used for legitimate system utility tasks as described in the skill documentation.\n- [External Downloads] (LOW): Network interaction targetsapi.squaads.comandapi.github.com, which are not included in the specific trusted domain whitelist for exfiltration analysis.
Audit Metadata