mlb-league-state-reader
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Yahoo Fantasy Baseball web pages and user-provided pastes, creating a potential surface for indirect prompt injection attacks. \n- Ingestion points: The skill uses the
mcp__claude-in-chrome__get_page_texttool to read external web content and prompts the user to paste page contents as a fallback (SKILL.md, resources/methodology.md). \n- Boundary markers: The instructions do not define clear delimiters or specific warnings to ignore instructions embedded within the ingested data. \n- Capability inventory: The agent has permissions to write to the local file system, specifically updatingteam-profile.mdand creating signal files in thesignals/directory. \n- Sanitization: While the skill uses regex patterns for data extraction (resources/methodology.md), it lacks explicit security sanitization to prevent malicious instructions in the source text from influencing agent behavior.
Audit Metadata