organization-best-practices

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs users to run npx auth@latest migrate during setup. The auth package is a generic third-party package on the NPM registry that does not match the better-auth vendor namespace patterns. Executing unverified packages via npx can lead to the execution of unintended or malicious code in the user's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines configuration for sending invitation emails that interpolate untrusted user-controlled data directly into HTML templates. This creates a vulnerability to content or prompt injection within the generated emails.
  • Ingestion points: The sendInvitationEmail hook in SKILL.md interpolates inviter.user.name and organization.name into HTML.
  • Boundary markers: No delimiters or isolation techniques are employed for the interpolated variables.
  • Capability inventory: The skill utilizes a network-based email delivery capability (sendEmail).
  • Sanitization: The code examples lack sanitization, HTML escaping, or validation for the injected user data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 03:24 PM
Security Audit — agent-trust-hub — organization-best-practices