monitor-contacts
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The SKILL.md file contains Continuous Operation instructions that direct the agent to act autonomously and bypass human interaction (e.g., 'agent MUST NOT stop and wait for the human'). It also presents an indirect prompt injection surface: \n
- Ingestion points: Processes external research data from /dogpile and /discover-contacts.\n
- Boundary markers: No explicit delimiters or instruction-bypass warnings are defined for the ingested data.\n
- Capability inventory: Bash command execution, filesystem access (Read/Write), and Discord webhook notifications.\n
- Sanitization: There is no evidence of sanitization or validation for the data retrieved from external research tools.\n- [COMMAND_EXECUTION]: The skill manages lifecycle operations through shell scripts (run.sh, sanity.sh). Additionally, memory_integration.py performs dynamic loading of Python code from a sibling directory (../taxonomy/taxonomy.py) using importlib.util.spec_from_file_location, which allows for the execution of code outside the skill's own scope.\n- [DATA_EXFILTRATION]: The skill transmits research summaries and contact change details to an external Discord webhook specified by the DISCORD_CONTACTS_WEBHOOK environment variable.
Audit Metadata