mlb-league-state-reader

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Yahoo Fantasy Baseball web pages and user-provided pastes, creating a potential surface for indirect prompt injection attacks. \n- Ingestion points: The skill uses the mcp__claude-in-chrome__get_page_text tool to read external web content and prompts the user to paste page contents as a fallback (SKILL.md, resources/methodology.md). \n- Boundary markers: The instructions do not define clear delimiters or specific warnings to ignore instructions embedded within the ingested data. \n- Capability inventory: The agent has permissions to write to the local file system, specifically updating team-profile.md and creating signal files in the signals/ directory. \n- Sanitization: While the skill uses regex patterns for data extraction (resources/methodology.md), it lacks explicit security sanitization to prevent malicious instructions in the source text from influencing agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:59 AM
Security Audit — agent-trust-hub — mlb-league-state-reader