skills/ericrisco/rsc-harness/suggest/Gen Agent Trust Hub

suggest

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and installs new agent capabilities from the vendor's repository using the npx @ericrisco/rsc add <id> command. This is a core management feature and requires user confirmation for each installation.
  • [COMMAND_EXECUTION]: The skill invokes various command-line tools to maintain project health, including npx @ericrisco/rsc doctor for diagnostics, npx @ericrisco/rsc repair for fixing harness configuration issues, and npx @ericrisco/rsc sync to align the environment with project metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes all user inputs to detect missing capabilities and classify intent, creating a surface where malicious prompts could influence suggestions.
  • Ingestion points: The skill logic processes every user turn at the beginning of the session and after every compaction event (SKILL.md).
  • Boundary markers: The skill does not implement specific delimiters or explicit warnings to the agent to ignore instructions embedded within the user data it processes.
  • Capability inventory: The skill has the ability to execute management-level CLI tools, perform package installations via npx, and modify project configuration files like .rsc.json.
  • Sanitization: The skill does not perform explicit filtering or validation of user-provided task descriptions before using them to query the skill catalog for matches.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — suggest