add-cursor-ambassador
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to SQL injection because it interpolates user-provided input (name, email, or UUID) directly into SQL query templates without sanitization or parameterization.
- Ingestion points: User-provided search terms for name, email, or UUID identifiers in
SKILL.md. - Boundary markers: Absent; user input is placed directly inside single quotes within the SQL queries.
- Capability inventory: The skill uses the
execute_sqltool on the Supabase projectknhgkaawjfqqwmsgmxnsto perform reads and updates on thepublic.userstable. - Sanitization: Absent; the instructions rely on simple string replacement (e.g.,
'<email>') which can be exploited with common SQL injection payloads. - [DATA_EXFILTRATION]: The skill is designed to retrieve and display sensitive PII (Personally Identifiable Information), including user email addresses and internal database UUIDs, which are then shown to the agent and potentially the user.
- Evidence: The workflow in
SKILL.mdexplicitly instructs the agent toSELECT id, name, slug, email, is_ambassadorand "Show a short table (name, slug, email)" to the user for disambiguation.
Audit Metadata