skill-lookup
Fail
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill automates the retrieval and installation of arbitrary files, including scripts, from the prompts.chat registry. This allows unverified remote content to be persisted in the local execution environment, where it can later be executed by the agent system.
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to malicious instructions embedded in the third-party skills it retrieves from the registry.
- Ingestion points: External skill content retrieved via the
get_skilltool from the prompts.chat API. - Boundary markers: The instructions lack delimiters or explicit warnings to ignore embedded commands or instructions in the downloaded content.
- Capability inventory: The agent is granted the ability to write files to the
.claude/skills/directory, which is a core configuration path. - Sanitization: There is no verification or sanitization of the downloaded markdown or script content beyond checking if the YAML frontmatter exists.
- [DYNAMIC_EXECUTION]: The skill installs scripts and helper files from an external source into a directory intended for active skills, enabling the dynamic loading of untrusted code into the agent's runtime environment.
- [COMMAND_EXECUTION]: The workflow requires the agent to perform file system writes and directory creation based on external metadata (e.g., skill slugs and filenames), which could be exploited for path traversal if the remote registry provides malicious metadata.
Recommendations
- AI detected serious security threats
Audit Metadata