discover-contacts
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The file
memory_integration.pyuses dynamic module loading to integrate with a taxonomy system. It constructs a path to a sibling directory and executes the code found at that path usingimportlib.util.spec_from_file_locationandexec_module. This dynamic execution of computed paths is a significant capability that can be misused if the local environment is manipulated. - [PROMPT_INJECTION]: The skill processes untrusted external data from contact lists and is susceptible to indirect prompt injection because it interpolates this data into tool calls.
- Ingestion points: Data enters the system through the
enrichcommand inrun.sh, which reads user-provided CSV and YAML files. - Boundary markers: The skill does not use explicit delimiters or instructions to the agent to ignore embedded commands within the contact data during interpolation into queries like
/dogpile "{first_name} {last_name} ...". - Capability inventory: The skill utilizes
run.shfor subprocess execution and has the ability to write enriched data to the/memorysystem and local disk storage. - Sanitization: No sanitization or validation of the input strings is performed before they are interpolated into prompts for the downstream research tools.
- [EXTERNAL_DOWNLOADS]: The
run.shscript ensures required dependencies are present by installing thelogurupackage from the standard registry viauv pipduring initialization.
Audit Metadata