workspace-surface-audit

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructs the agent to access and read sensitive file paths within the workspace. Specifically, it targets .env* files, .mcp.json, and .claude/settings*.json. These files are standard locations for storing API keys, authentication tokens, and other sensitive credentials. Although the skill includes a safety instruction to 'Never print secret values,' the act of reading these files into the agent's context increases the risk of accidental exposure or exfiltration by subsequent interactions.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection by ingesting data from untrusted files within a repository.
  • Ingestion points: The skill reads multiple files that may be attacker-controlled, including package.json, lockfiles, README.md, AGENTS.md, and CLAUDE.md (SKILL.md).
  • Boundary markers: No specific boundary markers or instructions are provided to the agent to treat the content of these files as data rather than instructions, nor are there warnings to ignore embedded commands.
  • Capability inventory: The skill is described as a 'Read-only audit,' but its primary purpose is to recommend the implementation of 'ECC-native skills, hooks, agents, and operator workflows,' which could lead to the execution of untrusted instructions if they are successfully injected into the audit process.
  • Sanitization: The instructions do not specify any sanitization, filtering, or validation steps for the content retrieved from the repository files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — workspace-surface-audit