peer-messaging
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the user to install the
claude-peers-mcppackage from the global NPM registry, which is an external and unverifiable dependency. - [REMOTE_CODE_EXECUTION]: The setup process involves executing code from an external source via
npx claude-peers-mcp, which runs third-party code on the local machine. - [PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection via the peer messaging protocol.
- Ingestion points: The agent receives untrusted data through the
check_messagestool, which retrieves messages from other Claude sessions via a local broker referenced inSKILL.md. - Boundary markers: There are no instructions provided to the agent to treat these incoming messages as potentially malicious or to separate them from its core instructions using delimiters.
- Capability inventory: As a Claude Code skill, the agent has broad access to shell commands and file systems, meaning instructions embedded in messages could be executed with significant privileges.
- Sanitization: No validation or sanitization of message content is described, allowing arbitrary strings to be placed directly into the agent's context.
Audit Metadata