claude-ecosystem-promoter
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection attacks through its use of web-browsing capabilities combined with sensitive system access.
- Ingestion points: The skill is designed to use
mcp__brave-search__brave_web_search,mcp__firecrawl__firecrawl_search,mcp__fetch__fetch, andWebFetchto gather information from the internet. - Boundary markers: The instructions lack specific guidance or delimiters to prevent the agent from following instructions that may be embedded in the HTML or content of external websites it visits.
- Capability inventory: The agent environment includes access to
Bash,Write, andEdit, which represent significant risk if the agent is manipulated by untrusted external data. - Sanitization: There are no defined mechanisms to sanitize or validate content retrieved from the web before it is incorporated into the agent's context.
- [EXTERNAL_DOWNLOADS]: The skill directs users and the agent to various external platforms and registries.
- References multiple third-party registries including Smithery.ai, Glama.ai, PulseMCP.com, SkillsMP.com, and MCPMarket.com for tool discovery and submission.
- Directs users to official GitHub repositories under the
modelcontextprotocolandanthropicsorganizations for registry submissions.
Audit Metadata