suggest
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads and installs new agent capabilities from the vendor's repository using the
npx @ericrisco/rsc add <id>command. This is a core management feature and requires user confirmation for each installation. - [COMMAND_EXECUTION]: The skill invokes various command-line tools to maintain project health, including
npx @ericrisco/rsc doctorfor diagnostics,npx @ericrisco/rsc repairfor fixing harness configuration issues, andnpx @ericrisco/rsc syncto align the environment with project metadata. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes all user inputs to detect missing capabilities and classify intent, creating a surface where malicious prompts could influence suggestions.
- Ingestion points: The skill logic processes every user turn at the beginning of the session and after every compaction event (SKILL.md).
- Boundary markers: The skill does not implement specific delimiters or explicit warnings to the agent to ignore instructions embedded within the user data it processes.
- Capability inventory: The skill has the ability to execute management-level CLI tools, perform package installations via npx, and modify project configuration files like .rsc.json.
- Sanitization: The skill does not perform explicit filtering or validation of user-provided task descriptions before using them to query the skill catalog for matches.
Audit Metadata