related-skills-surfacer
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill ingests metadata from an external 'registry cache' and monitors activity logs from other plugins to generate tool recommendations. This creates a surface where maliciously crafted skill descriptions in the registry could influence the agent's behavior or deceive the user into executing installation commands for harmful plugins.
- Ingestion points: Processes content from the registry-browser cache, other plugin activity records, and the practice profile located at
~/.claude/plugins/config/claude-for-legal/legal-builder-hub/CLAUDE.md. - Boundary markers: Absent. The instructions do not define any delimiters or system-level warnings to distinguish between the agent's core instructions and the potentially untrusted data from the registry.
- Capability inventory: The skill outputs recommendations that include direct executable commands for the user (e.g.,
/legal-builder-hub:skill-installer [name]). - Sanitization: Absent. The skill does not implement any validation, escaping, or filtering for the keyword-matched content retrieved from the external registry before presenting it to the user.
Audit Metadata