search-first
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions suggest checking
~/.claude/settings.jsonand~/.claude/skills/. While these paths can contain configuration data or API keys, the context is for discovering available local tools and capabilities (MCP servers and skills), which is standard practice in the Claude Code environment. - [COMMAND_EXECUTION]: The workflow encourages using standard development tools such as
rg(ripgrep) for local code search and package managers (npm,pip) for installing software. These recommendations focus on well-known, legitimate development utilities. - [EXTERNAL_DOWNLOADS]: The skill provides a list of recommended libraries and tools (e.g., Prettier, ESLint, Zod, Pydantic). These are well-known, trusted industry-standard packages, and their inclusion for reference does not pose a security risk.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates an attack surface by instructing the agent to ingest and evaluate data from external sources (npm, PyPI, GitHub search results) and then perform actions like package installation. While this creates a trust chain exposure, the skill itself provides the logical framework for evaluation rather than executing unverified payloads.
- Ingestion points: Research results from external package registries and GitHub repositories (SKILL.md, Full Mode section).
- Boundary markers: None explicitly defined in the instructions.
- Capability inventory: Package installation (
npm install,pip install) and file system reads (rg). - Sanitization: Not explicitly defined; relies on the agent's evaluation logic.
Audit Metadata