summon
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Executes the corvalis-recon binary located in the user's home directory (~/.claude/bin/corvalis-recon) to generate structured repository analysis.
- [COMMAND_EXECUTION]: Invokes a local Python script (skills/ui-ux-pro-max/scripts/search.py) to retrieve design system recommendations based on user-provided keywords.
- [EXTERNAL_DOWNLOADS]: Dispatches background agents to perform web research using standard search and fetch tools, targeting reputable engineering sources like Cloudflare, Stripe, and Vercel.
- [PROMPT_INJECTION]: Employs sub-agent prompt templates to guide background research tasks, providing specific context and formatting requirements for synthesized findings.
- [DATA_EXFILTRATION]: Processes repository metadata (symbols, dependencies, entry points) and provides synthesized summaries to background research agents for architectural comparison.
- [PROMPT_INJECTION]: Implements defensive measures against indirect prompt injection. Ingestion points include web research and repository metadata; boundary markers include the mandatory use of the auto-web-validation skill; the capability inventory includes subprocess execution and file-write operations; and sanitization is managed by instructing agents to corroborate findings and flag any manipulative content or instructions found in external sources.
Audit Metadata