developer-growth-analysis

Fail

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: HIGHDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is designed to read the local file ~/.claude/history.jsonl. This file contains sensitive information including every message sent to the agent and pastedContents, which often includes source code, configuration files, and potentially hardcoded credentials.
  • [DATA_EXFILTRATION]: The skill transmits summaries and specific details derived from the sensitive local history file to an external service (Slack) using the RUBE_MULTI_EXECUTE_TOOL. This creates a path for potentially sensitive data to leave the local environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by ingesting untrusted data from past chat interactions.
  • Ingestion points: The skill reads ~/.claude/history.jsonl and processes the display and pastedContents fields.
  • Boundary markers: None identified. The instructions do not specify any delimiters or warnings to ignore embedded instructions within the history file.
  • Capability inventory: The skill has the ability to send messages to external Slack DMs (RUBE_MULTI_EXECUTE_TOOL) and perform web searches on HackerNews (RUBE_SEARCH_TOOLS).
  • Sanitization: There is no evidence of sanitization, filtering, or escaping of the chat history content before it is processed by the LLM or sent to the Slack integration.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 8, 2026, 09:52 PM