init
Warn
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines an 'accompaniment dial' where the 'L0 — cavernícola' level explicitly instructs the agent to provide results with 'almost no explanation' and 'stop talking'. This pattern encourages the agent to conceal its internal reasoning and steps from the user, which reduces transparency and oversight. Furthermore, the skill describes a 'danger guard' intended to block irreversible commands but provides instructions on how to bypass or disable it (via the
.rsc/.no-danger-guardmarker). - [COMMAND_EXECUTION]: The skill instructs the agent to perform package installations and system audits using the terminal. It uses the command
npx @ericrisco/rsc add <ids>to install additional skills andnpx @ericrisco/rsc auditto inventory the workspace. These commands execute code from the author's own package registry. - [EXTERNAL_DOWNLOADS]: The instructions suggest adding a remote Model Context Protocol (MCP) server via
https://mcp.context7.com/mcpto fetch live library documentation. This establishes a connection to an external third-party service at runtime. - [INDIRECT_PROMPT_INJECTION]: The skill performs discovery by reading untrusted data from local project files.
- Ingestion points: Project manifests such as
package.json,pyproject.toml,pubspec.yaml,go.mod,Cargo.toml,Gemfile, andcomposer.jsonare read to detect the project stack. - Boundary markers: The instructions do not specify any delimiters or warnings for the agent to ignore potentially malicious content within these files.
- Capability inventory: The agent has the capability to execute shell commands (
npx), write files to the documentation directories, and access network resources via MCP. - Sanitization: There is no mention of sanitization or validation of the content ingested from these project manifests before it influences the agent's recommendations.
Audit Metadata