skills/letta-ai/skills/morph-warpgrep/Gen Agent Trust Hub

morph-warpgrep

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install the Morph SDK (@morphllm/morphsdk) and an MCP server (@morphllm/morphmcp) from the NPM registry. It also suggests cloning a test repository (https://github.com/letta-ai/letta-code.git) and installing system tools like ripgrep. These downloads target standard package registries and official repositories associated with the skill's purpose.
  • [COMMAND_EXECUTION]: The skill instructs users to run commands for package installation (bun add, npm install), system tool setup (brew install, sudo apt install), and execution of a local test script (bun ../scripts/test-warpgrep.ts .). These operations are consistent with the documented setup process for a developer integration.
  • [INDIRECT_PROMPT_INJECTION]: The integration involves WarpGrep, a tool designed to read and search local codebases. This creates a data ingestion surface where the agent processes external, potentially untrusted source code.
  • Ingestion points: Filesystem access in scripts/test-warpgrep.ts and via the SDK's internal search tools (grep, read, list_dir).
  • Boundary markers: The skill does not explicitly define delimiters for code search results, relying on the agent platform's tool output handling.
  • Capability inventory: The skill facilitates codebase search (read), directory listing, and code application (write/edit) via the Morph API.
  • Sanitization: No specific sanitization or filtering of codebase content is implemented within the provided skill scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — morph-warpgrep