readout

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill implements a version check mechanism that queries the vendor's API at https://foundry.thehorizonfoundry.com/api/version to notify the user of available updates.- [COMMAND_EXECUTION]: The skill utilizes shell commands including find, mkdir, curl, and touch to execute the update check and manage its state.- [PERSISTENCE]: The skill creates a hidden directory and a timestamp file at ~/.claude/.foundry-version-checked to maintain state and rate-limit version checks across different sessions.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external data surfaces (dashboards, reports) which introduces a vulnerability surface for indirect prompt injection.
  • Ingestion points: Project files, deploy logs, configuration history, and rendered images of external data surfaces.
  • Boundary markers: The skill does not provide specific instructions for using delimiters or boundary markers to isolate potentially malicious data.
  • Capability inventory: The skill has access to shell execution, network requests via curl, and file system writes to both the project and the user's home directory.
  • Sanitization: No automated sanitization or filtering of the ingested surface content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 11:44 AM
Security Audit — agent-trust-hub — readout