related-skills-surfacer

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill ingests metadata from an external 'registry cache' and monitors activity logs from other plugins to generate tool recommendations. This creates a surface where maliciously crafted skill descriptions in the registry could influence the agent's behavior or deceive the user into executing installation commands for harmful plugins.
  • Ingestion points: Processes content from the registry-browser cache, other plugin activity records, and the practice profile located at ~/.claude/plugins/config/claude-for-legal/legal-builder-hub/CLAUDE.md.
  • Boundary markers: Absent. The instructions do not define any delimiters or system-level warnings to distinguish between the agent's core instructions and the potentially untrusted data from the registry.
  • Capability inventory: The skill outputs recommendations that include direct executable commands for the user (e.g., /legal-builder-hub:skill-installer [name]).
  • Sanitization: Absent. The skill does not implement any validation, escaping, or filtering for the keyword-matched content retrieved from the external registry before presenting it to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — related-skills-surfacer