basecamp-connect

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill manages agent configuration by executing subcommands of the basecamp CLI. It implements a comprehensive 'Shell quoting rule' to prevent command injection, instructing the agent to validate numeric IDs and single-quote all other string values while properly escaping internal single quotes.
  • [PERSISTENCE]: The skill manages the lifecycle of the agent connector through systemd user services. It provides instructions for service installation, uninstallation, and status verification using systemctl, ensuring the connector can reliably run in the background.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data originating from Basecamp API responses and logs.
  • Ingestion points: Data ingested via basecamp projects list, basecamp me, and journalctl logs.
  • Boundary markers: Explicit instructions to quote all string values in shell commands and validate numeric IDs.
  • Capability inventory: The skill uses the basecamp CLI and systemctl to perform its primary functions.
  • Sanitization: Strictly enforces the use of CLI-native authentication and shell-safe quoting for all external data interpolation.
  • [CREDENTIALS_SAFE]: The skill contains explicit safety directives prohibiting the agent from asking for, printing, or storing tokens, secrets, or passwords. It mandates the use of the CLI's internal profile-based credential store and warns against using unsafe authentication flags.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 04:03 PM