docs-seeker

Fail

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's core workflows in SKILL.md and multiple workflow files (e.g., workflows/topic-search.md) instruct the agent to execute shell commands that interpolate raw user input (e.g., node scripts/detect-topic.js "<user query>"). This pattern is highly susceptible to shell command injection if the input contains malicious shell metacharacters.
  • [REMOTE_CODE_EXECUTION]: The repository analysis workflow (workflows/repo-analysis.md) directs the agent to git clone arbitrary external repositories and process their content using tools like repomix. Executing logic on untrusted, externally sourced code structures presents a significant remote code execution risk.
  • [EXTERNAL_DOWNLOADS]: The scripts/fetch-docs.js script fetches documentation from context7.com, a third-party service. While central to the skill, this involves transmitting user-derived queries and potentially API keys to an external domain.
  • [CREDENTIALS_UNSAFE]: The scripts/utils/env-loader.js utility traverses the directory tree up to the .claude/ root to find and load .env files. This allows the skill's scripts to access sensitive environment variables and credentials stored across the agent's environment.
  • [PROMPT_INJECTION]: The skill processes untrusted external documentation (llms.txt) and repository contents which could contain Indirect Prompt Injection attacks. Ingestion points: content fetched via fetch-docs.js and repo-analysis.md. Capability inventory: shell execution, network requests, and filesystem access. Sanitization: None detected. Boundary markers: None present.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — docs-seeker