organization-best-practices
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs users to run
npx auth@latest migrateduring setup. Theauthpackage is a generic third-party package on the NPM registry that does not match thebetter-authvendor namespace patterns. Executing unverified packages via npx can lead to the execution of unintended or malicious code in the user's environment. - [INDIRECT_PROMPT_INJECTION]: The skill defines configuration for sending invitation emails that interpolate untrusted user-controlled data directly into HTML templates. This creates a vulnerability to content or prompt injection within the generated emails.
- Ingestion points: The
sendInvitationEmailhook in SKILL.md interpolatesinviter.user.nameandorganization.nameinto HTML. - Boundary markers: No delimiters or isolation techniques are employed for the interpolated variables.
- Capability inventory: The skill utilizes a network-based email delivery capability (
sendEmail). - Sanitization: The code examples lack sanitization, HTML escaping, or validation for the injected user data.
Audit Metadata