developer-growth-analysis
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses the local file
~/.claude/history.jsonl, which contains private user conversation history, project metadata, and pasted code snippets from Claude Code sessions. - [DATA_EXFILTRATION]: Summarized data and insights derived from the private chat history are transmitted to Slack via the
RUBE_MULTI_EXECUTE_TOOLto deliver the report to user DMs. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from local chat logs which may contain instructions embedded in previously viewed code or web content that could influence agent behavior during analysis.
- Ingestion points:
~/.claude/history.jsonl(referenced in SKILL.md). - Boundary markers: Absent; no specific delimiters are used to isolate ingested chat data from instructions.
- Capability inventory: Reading local files, performing network searches on HackerNews, and sending messages to Slack via Rube MCP tools.
- Sanitization: Absent; the skill extracts and summarizes content directly from the logs without filtering for potential injection patterns.
Recommendations
- AI detected serious security threats
Audit Metadata