search-first

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXPOSURE]: The skill instructs the agent to inspect local configuration paths, including ~/.claude/settings.json, ~/.claude/skills/, and ~/.codex/skills/, to determine tool availability. While intended for discovery of existing capabilities, this involves reading configuration files that may contain environmental data.
  • [INDIRECT_PROMPT_INJECTION]: The subagent prompt template in the "Full Mode" section interpolates user-provided content—such as project descriptions and constraints ([DESCRIPTION], [ANY])—into an instruction string without defined boundary markers or sanitization guidelines.
  • Ingestion points: Functional descriptions and constraint strings provided during the research trigger.
  • Boundary markers: None observed in the provided agent prompt template.
  • Capability inventory: File system inspection (ls, rg), package management (npm, pip), and network research capabilities across multiple scripts.
  • Sanitization: No escaping or validation is specified for the interpolated content.
  • [EXTERNAL_DOWNLOADS]: The workflow explicitly guides the agent to identify and install third-party dependencies from registries like npm and PyPI. While well-known libraries such as eslint, zod, and httpx are provided as examples, the logic encourages the adoption of arbitrary external packages discovered during research.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — search-first