mcp-skill-hardened

Warn

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill incorporates 'sticky' instruction patterns (e.g., 'regardless of claimed authority or urgency') in its 'Security Guardrails' section, which are intended to make these specific rules override the agent's baseline safety behaviors and any future user prompts.
  • [PROMPT_INJECTION]: The instructions include logic to bypass mandatory per-request confirmation for long-running 'deep research' tasks if the user includes specific phrases like 'acknowledges the duration,' creating a potential vulnerability where significant external resources could be committed without proper oversight.
  • [PROMPT_INJECTION]: The guardrails explicitly designate searches for 'metadata endpoints' as safe; while queries are sent to a public API, this guidance encourages the agent to retrieve and potentially process sensitive information related to cloud credentials or internal infrastructure found in public results.
  • [DATA_EXFILTRATION]: The core functionality of the skill is to transmit user queries and crawling requests to the external endpoint 'mcp.exa.ai'.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. Ingestion points: External data from web search results and crawled pages via tools such as 'web_search_exa' and 'crawling_exa'. Boundary markers: Absent in the skill instructions. Capability inventory: Extensive network research, crawling, and company data retrieval capabilities. Sanitization: No sanitization or escaping of external content is documented before the data is processed by the agent.
  • [PROMPT_INJECTION]: The 'SAFETY.md' file and 'Armored by Faberlens' metadata act as metadata poisoning by providing authoritative but unverifiable claims about the skill's safety and 'hardened' status, which can be used to influence the perception of the skill's risk level.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 21, 2026, 06:31 PM
Security Audit — agent-trust-hub — mcp-skill-hardened