add-cursor-ambassador

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to SQL injection because it interpolates user-provided input (name, email, or UUID) directly into SQL query templates without sanitization or parameterization.
  • Ingestion points: User-provided search terms for name, email, or UUID identifiers in SKILL.md.
  • Boundary markers: Absent; user input is placed directly inside single quotes within the SQL queries.
  • Capability inventory: The skill uses the execute_sql tool on the Supabase project knhgkaawjfqqwmsgmxns to perform reads and updates on the public.users table.
  • Sanitization: Absent; the instructions rely on simple string replacement (e.g., '<email>') which can be exploited with common SQL injection payloads.
  • [DATA_EXFILTRATION]: The skill is designed to retrieve and display sensitive PII (Personally Identifiable Information), including user email addresses and internal database UUIDs, which are then shown to the agent and potentially the user.
  • Evidence: The workflow in SKILL.md explicitly instructs the agent to SELECT id, name, slug, email, is_ambassador and "Show a short table (name, slug, email)" to the user for disambiguation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:39 PM
Security Audit — agent-trust-hub — add-cursor-ambassador