x-collect
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from web search results, which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Web search results retrieved during four rounds of research (SKILL.md).
- Boundary markers: Absent; search results are processed and synthesized without explicit delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill executes a local Python script (
x_state.py) and generates structured JSON output based on external findings (SKILL.md). - Sanitization: Absent; the instructions do not specify sanitization or validation of content retrieved from the web before it is used in reports or event payloads.
- [COMMAND_EXECUTION]: The skill executes a local Python script to manage state events and track research completion.
- Evidence: The execution of
python ~/.claude/skills/x-create/scripts/x_state.pyin the final execution step (SKILL.md). - Context: This script manages vendor-specific state files and telemetry within the
~/.claude/skills/x-create/directory structure.
Audit Metadata