content-engine
Fail
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to modify the source code of other installed skills within the internal application directory (
~/.claude/skills/<slug>-command-base/SKILL.md). Instructing an agent to rewrite its own or other skills' instructions is a form of privilege escalation and can be used to bypass safety controls or establish persistence. - [COMMAND_EXECUTION]: The skill directs the agent to perform broad recursive globbing (
**/Content-Engine/content-engine-paths.md) to scan the user's entire workspace for configuration files. This capability could be abused to locate and access sensitive data outside the intended scope of the skill. - [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, such as WhatsApp logs, social media reviews, and community comments. This creates a large attack surface for indirect prompt injection, particularly as the skill has the authority to write to the file system and modify agent instructions.
Recommendations
- AI detected serious security threats
Audit Metadata