skill-lookup
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of content from an external registry and writes it to the local filesystem, establishing an attack surface for indirect prompt injection. If the source content contains malicious instructions, they could influence the agent's behavior once the files are saved to the local directory.
- Ingestion points: Data retrieved from the prompts.chat MCP server via the get_skill tool.
- Boundary markers: Absent; there are no instructions to isolate or delimit external content during the installation process.
- Capability inventory: Instructions provide for directory creation and file writing (including scripts) to the .claude/skills/ path.
- Sanitization: No validation or sanitization of the downloaded file contents is mentioned before they are saved to disk.
- [EXTERNAL_DOWNLOADS]: The skill retrieves skill configurations, instructions, and scripts from the external prompts.chat service.
Audit Metadata