skills/mblode/claude-code-search/ccs/Gen Agent Trust Hub

ccs

Warn

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is designed to access and expose sensitive user data by reading from local directories that store session and prompt history. This includes access to ~/.claude/projects/, ~/.codex/sessions/, and the Cursor editor's global storage database (state.vscdb). Historical prompts often contain sensitive information, source code, or internal project details.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install an external, unversioned Node.js package globally using npm install -g claude-code-search. This introduces a dependency on a third-party resource that is not managed within the skill's own distribution.
  • [COMMAND_EXECUTION]: The skill uses the ccs CLI tool to execute local commands. While intended for searching history, this capability allows the agent to interact with the underlying operating system and file system.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted historical data which creates a vulnerability to indirect prompt injection if those past prompts contain malicious instructions.
  • Ingestion points: The agent reads content from local prompt history files (SKILL.md).
  • Boundary markers: Absent; there are no instructions or delimiters provided to prevent the agent from following instructions that might be embedded within the retrieved prompt text.
  • Capability inventory: The skill allows for local file system reading and shell command execution via the ccs tool.
  • Sanitization: Absent; no methods for sanitizing, escaping, or filtering the retrieved prompt history are mentioned.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 29, 2026, 03:53 AM
Security Audit — agent-trust-hub — ccs