ms
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/mcp-search.pyexecutes a local binary (defaulting toms) to perform skill searches. It correctly avoids shell execution by passing arguments as a list and usesshlex.splitto safely parse the binary path from theMS_BINenvironment variable. It also manages the lifecycle of the search process correctly using process groups (start_new_session=True) to ensure clean termination. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a search engine for other AI skills, creating a surface where malicious instructions embedded in the indexed content or crafted queries could potentially influence the agent.
- Ingestion points: User-provided search queries and the contents of retrieved
SKILL.mdfiles processed via the search helper. - Boundary markers: Search results are encapsulated in structured JSON objects, separating metadata from full guidance content.
- Capability inventory: The skill can execute the local
mssearch binary via subprocess. - Sanitization: Search queries are JSON-encoded to prevent protocol-level injection, and retrieved data is parsed through standard JSON libraries.
Audit Metadata