claude-ecosystem-promoter

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection attacks through its use of web-browsing capabilities combined with sensitive system access.
  • Ingestion points: The skill is designed to use mcp__brave-search__brave_web_search, mcp__firecrawl__firecrawl_search, mcp__fetch__fetch, and WebFetch to gather information from the internet.
  • Boundary markers: The instructions lack specific guidance or delimiters to prevent the agent from following instructions that may be embedded in the HTML or content of external websites it visits.
  • Capability inventory: The agent environment includes access to Bash, Write, and Edit, which represent significant risk if the agent is manipulated by untrusted external data.
  • Sanitization: There are no defined mechanisms to sanitize or validate content retrieved from the web before it is incorporated into the agent's context.
  • [EXTERNAL_DOWNLOADS]: The skill directs users and the agent to various external platforms and registries.
  • References multiple third-party registries including Smithery.ai, Glama.ai, PulseMCP.com, SkillsMP.com, and MCPMarket.com for tool discovery and submission.
  • Directs users to official GitHub repositories under the modelcontextprotocol and anthropics organizations for registry submissions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — claude-ecosystem-promoter