docs-seeker
Fail
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's core workflows in SKILL.md and multiple workflow files (e.g., workflows/topic-search.md) instruct the agent to execute shell commands that interpolate raw user input (e.g.,
node scripts/detect-topic.js "<user query>"). This pattern is highly susceptible to shell command injection if the input contains malicious shell metacharacters. - [REMOTE_CODE_EXECUTION]: The repository analysis workflow (workflows/repo-analysis.md) directs the agent to
git clonearbitrary external repositories and process their content using tools likerepomix. Executing logic on untrusted, externally sourced code structures presents a significant remote code execution risk. - [EXTERNAL_DOWNLOADS]: The
scripts/fetch-docs.jsscript fetches documentation fromcontext7.com, a third-party service. While central to the skill, this involves transmitting user-derived queries and potentially API keys to an external domain. - [CREDENTIALS_UNSAFE]: The
scripts/utils/env-loader.jsutility traverses the directory tree up to the.claude/root to find and load.envfiles. This allows the skill's scripts to access sensitive environment variables and credentials stored across the agent's environment. - [PROMPT_INJECTION]: The skill processes untrusted external documentation (llms.txt) and repository contents which could contain Indirect Prompt Injection attacks. Ingestion points: content fetched via fetch-docs.js and repo-analysis.md. Capability inventory: shell execution, network requests, and filesystem access. Sanitization: None detected. Boundary markers: None present.
Recommendations
- AI detected serious security threats
Audit Metadata