market-research
Warn
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes several local binaries located in the
~/.claude/skills/econstack/bin/directory for update checks and project management. Specifically, it useseval "$(.../econstack-slug)"to execute shell commands generated dynamically by a local script, which is a high-risk pattern allowing for arbitrary code execution if the utility is compromised. - [EXTERNAL_DOWNLOADS]: The skill references and encourages the use of external code and data from GitHub. It suggests cloning
https://github.com/charlescoverdale/econstack-data.gitfor parameter support and performing agit pullfor skill updates. These third-party sources are not part of the established trusted vendor list. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted data from the public web and incorporates it into structured research reports.
- Ingestion points: Market data gathered via
WebSearchandWebFetchtools as described in Step 2 of the instructions. - Boundary markers: There are no explicit delimiters or instructions to the agent to ignore embedded commands within the fetched content.
- Capability inventory: The skill utilizes the
BashandWritetools, providing a surface for command execution or file modification guided by injected instructions. - Sanitization: No sanitization, validation, or filtering processes are defined for the external content before it is processed into the final report.
Audit Metadata