search-first
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXPOSURE]: The skill instructs the agent to inspect local configuration paths, including
~/.claude/settings.json,~/.claude/skills/, and~/.codex/skills/, to determine tool availability. While intended for discovery of existing capabilities, this involves reading configuration files that may contain environmental data. - [INDIRECT_PROMPT_INJECTION]: The subagent prompt template in the "Full Mode" section interpolates user-provided content—such as project descriptions and constraints (
[DESCRIPTION],[ANY])—into an instruction string without defined boundary markers or sanitization guidelines. - Ingestion points: Functional descriptions and constraint strings provided during the research trigger.
- Boundary markers: None observed in the provided agent prompt template.
- Capability inventory: File system inspection (
ls,rg), package management (npm,pip), and network research capabilities across multiple scripts. - Sanitization: No escaping or validation is specified for the interpolated content.
- [EXTERNAL_DOWNLOADS]: The workflow explicitly guides the agent to identify and install third-party dependencies from registries like npm and PyPI. While well-known libraries such as
eslint,zod, andhttpxare provided as examples, the logic encourages the adoption of arbitrary external packages discovered during research.
Audit Metadata