find-peers
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to identify, read, and 'adopt' patterns from external, public repositories found via Sourcegraph. This creates a surface for indirect prompt injection, where an attacker could host a repository containing malicious instructions designed to be interpreted by the AI agent during the learning phase.
- Ingestion points: Source code from external repositories identified via Sourcegraph and data returned by the
deepwikiMCP server. - Boundary markers: Absent. The instructions do not provide delimiters or warnings for the agent to ignore instructions that might be embedded in the external code or documentation it reads.
- Capability inventory: The agent has the authority to write to local files (e.g.,
.brain/resources/peers.svx) and perform git operations (committing the changes). - Sanitization: Absent. There are no instructions for the agent to sanitize or filter the external content before adopting code patterns into the local project.
- [COMMAND_EXECUTION]: The skill invokes the execution of a local shell command,
pnpm find-peers. This operation relies on the security and integrity of the scripts defined within the local project's environment.
Audit Metadata