basecamp-connect
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill manages agent configuration by executing subcommands of the
basecampCLI. It implements a comprehensive 'Shell quoting rule' to prevent command injection, instructing the agent to validate numeric IDs and single-quote all other string values while properly escaping internal single quotes. - [PERSISTENCE]: The skill manages the lifecycle of the agent connector through
systemduser services. It provides instructions for service installation, uninstallation, and status verification usingsystemctl, ensuring the connector can reliably run in the background. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data originating from Basecamp API responses and logs.
- Ingestion points: Data ingested via
basecamp projects list,basecamp me, andjournalctllogs. - Boundary markers: Explicit instructions to quote all string values in shell commands and validate numeric IDs.
- Capability inventory: The skill uses the
basecampCLI andsystemctlto perform its primary functions. - Sanitization: Strictly enforces the use of CLI-native authentication and shell-safe quoting for all external data interpolation.
- [CREDENTIALS_SAFE]: The skill contains explicit safety directives prohibiting the agent from asking for, printing, or storing tokens, secrets, or passwords. It mandates the use of the CLI's internal profile-based credential store and warns against using unsafe authentication flags.
Audit Metadata