cass
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill indexes and retrieves content from session histories generated by various AI coding agents. This external content is untrusted and may contain malicious instructions (e.g., hidden in code comments or project data) that could be interpreted by the current agent when using the search, view, or expand functionalities.
- Ingestion points: The
cass search,cass view,cass expand, andcass exportsubcommands ingest data from local session log files (.jsonl) generated by other tools. - Boundary markers: The skill instructions do not specify any delimiters or safety markers to isolate the retrieved session content from the agent's primary instruction set.
- Capability inventory: The agent has the ability to execute shell commands to interact with the
cassbinary and access the filesystem. - Sanitization: There is no documentation or implementation of sanitization, filtering, or escaping for the session content before it is processed by the agent.
- [DATA_EXFILTRATION]: The skill facilitates access to highly sensitive coding session histories. These histories often contain proprietary source code, internal architectural details, and potentially sensitive tokens or credentials that were inadvertently logged during previous development sessions.
- [EXTERNAL_DOWNLOADS]: The skill's setup instructions direct the user to install the
cassutility usingcargo install cass. This fetches and compiles a third-party binary from a remote repository. As the tool is associated with the skill's author, this is considered a vendor-owned resource.
Audit Metadata