comms-onboarding
Warn
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to download and execute code from the NPM registry at runtime using
npx -y. This allows for the execution of external code from the@agentcommsscope that has not been locally audited. - Evidence:
npx -y @agentcomms/core mcp install --client claude-codeinSKILL.md. - Evidence: The 'Without the MCP tools' section recommends running
npx -y @agentcomms/<package>for various service modules. - [COMMAND_EXECUTION]: The skill requires the agent to run numerous shell commands and CLI tools to register servers and manage communications.
- Evidence: References to
agent-gmail,agent-slack,agent-resend, andagent-whatsappCLI commands throughoutSKILL.md. - [EXTERNAL_DOWNLOADS]: The skill depends on fetching and installing external software packages to enable communication features.
- Evidence: Installation of core and service-specific MCP servers from external repositories.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from third-party communication platforms, which constitutes an attack surface for indirect prompt injection.
- Ingestion points: Data is pulled from Gmail, Slack, and WhatsApp accounts as described in
SKILL.md. - Boundary markers:
references/contract.md(Section 3) explicitly warns the agent to treat account data as information only and not as valid instructions. - Capability inventory: The skill has access to shell execution, server configuration tools, and sensitive file paths.
- Sanitization: The contract specifies that any requests for action found in external data must be reported to the user instead of being executed automatically.
- [CREDENTIALS_UNSAFE]: The skill workflow involves handling sensitive authentication files and configuration data.
- Evidence: Step 3 in
SKILL.mddirects the agent to use the path to a Google Cloud OAuth client JSON file. - Mitigation: The skill includes explicit guidelines never to accept or print secret contents in the chat, though the access to credential files remains a security-sensitive operation.
Audit Metadata