research
Warn
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements significant behavioral overrides and creates a high-risk surface for indirect prompt injection by mandating the ingestion of data from uncontrolled external sources. * Ingestion points: Untrusted data from web search results, GitHub, and StackOverflow as defined in SKILL.md. * Boundary markers: Missing delimiters or instructions to ignore embedded commands. * Capability inventory: Access to WebSearch, WebFetch, and package tools (npm/pnpx). * Sanitization: No filtering or escaping of external content.
- [EXTERNAL_DOWNLOADS]: The instructions mandate the use of npmx.dev for package information and strictly prohibit the use of the official npmjs.com registry, introducing supply chain risks through non-standard source redirection.
- [DATA_EXFILTRATION]: The mandatory research protocol requires the agent to transmit project details, architectural queries, and codebase traces to multiple external search engines and third-party websites.
- [REMOTE_CODE_EXECUTION]: The skill facilitates potential execution of malicious content by directing the agent to follow unverified solutions from web sources and relying on non-standard package metadata providers, increasing the likelihood of supply chain poisoning.
Audit Metadata