developer-growth-analysis
Fail
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: HIGHDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to read the local file
~/.claude/history.jsonl. This file contains sensitive information including every message sent to the agent andpastedContents, which often includes source code, configuration files, and potentially hardcoded credentials. - [DATA_EXFILTRATION]: The skill transmits summaries and specific details derived from the sensitive local history file to an external service (Slack) using the
RUBE_MULTI_EXECUTE_TOOL. This creates a path for potentially sensitive data to leave the local environment. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by ingesting untrusted data from past chat interactions.
- Ingestion points: The skill reads
~/.claude/history.jsonland processes thedisplayandpastedContentsfields. - Boundary markers: None identified. The instructions do not specify any delimiters or warnings to ignore embedded instructions within the history file.
- Capability inventory: The skill has the ability to send messages to external Slack DMs (
RUBE_MULTI_EXECUTE_TOOL) and perform web searches on HackerNews (RUBE_SEARCH_TOOLS). - Sanitization: There is no evidence of sanitization, filtering, or escaping of the chat history content before it is processed by the LLM or sent to the Slack integration.
Recommendations
- AI detected serious security threats
Audit Metadata