ccs
Warn
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to access and expose sensitive user data by reading from local directories that store session and prompt history. This includes access to
~/.claude/projects/,~/.codex/sessions/, and the Cursor editor's global storage database (state.vscdb). Historical prompts often contain sensitive information, source code, or internal project details. - [EXTERNAL_DOWNLOADS]: The skill instructs the user to install an external, unversioned Node.js package globally using
npm install -g claude-code-search. This introduces a dependency on a third-party resource that is not managed within the skill's own distribution. - [COMMAND_EXECUTION]: The skill uses the
ccsCLI tool to execute local commands. While intended for searching history, this capability allows the agent to interact with the underlying operating system and file system. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted historical data which creates a vulnerability to indirect prompt injection if those past prompts contain malicious instructions.
- Ingestion points: The agent reads content from local prompt history files (
SKILL.md). - Boundary markers: Absent; there are no instructions or delimiters provided to prevent the agent from following instructions that might be embedded within the retrieved prompt text.
- Capability inventory: The skill allows for local file system reading and shell command execution via the
ccstool. - Sanitization: Absent; no methods for sanitizing, escaping, or filtering the retrieved prompt history are mentioned.
Audit Metadata