skills/johnlindquist/claude/cass/Gen Agent Trust Hub

cass

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill indexes and retrieves content from session histories generated by various AI coding agents. This external content is untrusted and may contain malicious instructions (e.g., hidden in code comments or project data) that could be interpreted by the current agent when using the search, view, or expand functionalities.
  • Ingestion points: The cass search, cass view, cass expand, and cass export subcommands ingest data from local session log files (.jsonl) generated by other tools.
  • Boundary markers: The skill instructions do not specify any delimiters or safety markers to isolate the retrieved session content from the agent's primary instruction set.
  • Capability inventory: The agent has the ability to execute shell commands to interact with the cass binary and access the filesystem.
  • Sanitization: There is no documentation or implementation of sanitization, filtering, or escaping for the session content before it is processed by the agent.
  • [DATA_EXFILTRATION]: The skill facilitates access to highly sensitive coding session histories. These histories often contain proprietary source code, internal architectural details, and potentially sensitive tokens or credentials that were inadvertently logged during previous development sessions.
  • [EXTERNAL_DOWNLOADS]: The skill's setup instructions direct the user to install the cass utility using cargo install cass. This fetches and compiles a third-party binary from a remote repository. As the tool is associated with the skill's author, this is considered a vendor-owned resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:25 PM
Security Audit — agent-trust-hub — cass