peer-messaging

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the user to install the claude-peers-mcp package from the global NPM registry, which is an external and unverifiable dependency.
  • [REMOTE_CODE_EXECUTION]: The setup process involves executing code from an external source via npx claude-peers-mcp, which runs third-party code on the local machine.
  • [PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection via the peer messaging protocol.
  • Ingestion points: The agent receives untrusted data through the check_messages tool, which retrieves messages from other Claude sessions via a local broker referenced in SKILL.md.
  • Boundary markers: There are no instructions provided to the agent to treat these incoming messages as potentially malicious or to separate them from its core instructions using delimiters.
  • Capability inventory: As a Claude Code skill, the agent has broad access to shell commands and file systems, meaning instructions embedded in messages could be executed with significant privileges.
  • Sanitization: No validation or sanitization of message content is described, allowing arbitrary strings to be placed directly into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 06:17 PM
Security Audit — agent-trust-hub — peer-messaging