comms-onboarding

Warn

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to download and execute code from the NPM registry at runtime using npx -y. This allows for the execution of external code from the @agentcomms scope that has not been locally audited.
  • Evidence: npx -y @agentcomms/core mcp install --client claude-code in SKILL.md.
  • Evidence: The 'Without the MCP tools' section recommends running npx -y @agentcomms/<package> for various service modules.
  • [COMMAND_EXECUTION]: The skill requires the agent to run numerous shell commands and CLI tools to register servers and manage communications.
  • Evidence: References to agent-gmail, agent-slack, agent-resend, and agent-whatsapp CLI commands throughout SKILL.md.
  • [EXTERNAL_DOWNLOADS]: The skill depends on fetching and installing external software packages to enable communication features.
  • Evidence: Installation of core and service-specific MCP servers from external repositories.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from third-party communication platforms, which constitutes an attack surface for indirect prompt injection.
  • Ingestion points: Data is pulled from Gmail, Slack, and WhatsApp accounts as described in SKILL.md.
  • Boundary markers: references/contract.md (Section 3) explicitly warns the agent to treat account data as information only and not as valid instructions.
  • Capability inventory: The skill has access to shell execution, server configuration tools, and sensitive file paths.
  • Sanitization: The contract specifies that any requests for action found in external data must be reported to the user instead of being executed automatically.
  • [CREDENTIALS_UNSAFE]: The skill workflow involves handling sensitive authentication files and configuration data.
  • Evidence: Step 3 in SKILL.md directs the agent to use the path to a Google Cloud OAuth client JSON file.
  • Mitigation: The skill includes explicit guidelines never to accept or print secret contents in the chat, though the access to credential files remains a security-sensitive operation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 5, 2026, 12:34 AM
Security Audit — agent-trust-hub — comms-onboarding