discover-contacts

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The file memory_integration.py uses dynamic module loading to integrate with a taxonomy system. It constructs a path to a sibling directory and executes the code found at that path using importlib.util.spec_from_file_location and exec_module. This dynamic execution of computed paths is a significant capability that can be misused if the local environment is manipulated.
  • [PROMPT_INJECTION]: The skill processes untrusted external data from contact lists and is susceptible to indirect prompt injection because it interpolates this data into tool calls.
  • Ingestion points: Data enters the system through the enrich command in run.sh, which reads user-provided CSV and YAML files.
  • Boundary markers: The skill does not use explicit delimiters or instructions to the agent to ignore embedded commands within the contact data during interpolation into queries like /dogpile "{first_name} {last_name} ...".
  • Capability inventory: The skill utilizes run.sh for subprocess execution and has the ability to write enriched data to the /memory system and local disk storage.
  • Sanitization: No sanitization or validation of the input strings is performed before they are interpolated into prompts for the downstream research tools.
  • [EXTERNAL_DOWNLOADS]: The run.sh script ensures required dependencies are present by installing the loguru package from the standard registry via uv pip during initialization.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — discover-contacts