zvec-grep
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the
@zvec/zvec-greppackage via the Node Package Manager (npm). The instructions emphasize pinning the installation to version 0.2.2 from the public registry. - [COMMAND_EXECUTION]: The skill utilizes several CLI commands through the
zgbinary and the providedzvec-grep.shhelper script to perform workspace indexing, hybrid searches, and status checks. It also usesnpmfor installation tasks andnodefor runtime verification. - [PERSISTENCE]: The
zg installcommand is designed to modify local agent configuration files (such as~/.claude.json,~/.cursor/mcp.json, and others) to register the MCP server. This is the primary mechanism for maintaining the tool's integration across agent sessions. The skill specifies the use of managed blocks to preserve unrelated user settings during these modifications. - [INDIRECT_PROMPT_INJECTION]: The skill provides retrieval capabilities over untrusted local workspace data, which creates a potential surface for indirect prompt injection if malicious instructions are embedded in indexed files.
- Ingestion points: The
zg querycommand reads and processes content from the local workspace, including code files, Markdown, text, and structured data (JSON, YAML, CSV). - Boundary markers: The instructions recommend that the agent use result limits (
--limit) for semantic probes and verify findings with exact matches usingrgor direct file reads. - Capability inventory: The skill environment allows for the use of
Bash,Read,Write,Edit,Glob,Grep, andWebFetchtools. - Sanitization: The skill instructions do not implement specific data sanitization logic; it relies on the agent's internal processing of retrieved search results.
Audit Metadata