search-first
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines a workflow that ingests research data from external untrusted sources (web, GitHub, and package registries). This presents an indirect prompt injection surface where malicious instructions hidden in third-party content could influence the agent's behavior. Ingestion points: Research results fetched via the researcher agent; Boundary markers: Absent in the provided prompt template; Capability inventory: The skill allows for file writes, package installations, and code implementation based on research; Sanitization: No sanitization or validation of the retrieved external content is specified.
- [DATA_EXFILTRATION]: Instructions to check
~/.claude/settings.jsonand~/.claude/skills/for tool discovery involve accessing local configuration data. While intended for discovery of MCP servers and skills, these files may contain sensitive environment or integration details. - [COMMAND_EXECUTION]: The workflow directs the agent to install and use third-party packages (e.g., via
npm installorpip install) discovered through research, which relies on the agent's ability to verify the safety and integrity of external software.
Audit Metadata