people-property

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install and run the agentcash npm package, which is not from a recognized trusted organization or explicitly linked to the author's vendor patterns. This includes both global installation and the use of npx for runtime execution.
  • [COMMAND_EXECUTION]: The skill uses npx and npm shell commands to perform core tasks, including fetching data and managing account settings. This execution path could be targeted if inputs are not properly sanitized.
  • [DATA_EXFILTRATION]: Search queries containing sensitive personal information (names, addresses) are sent to stableenrich.dev, an external domain not associated with the vendor or the approved whitelist.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes structured responses from an external API, creating a surface for potential injection attacks if the API returns malicious content.
  • Ingestion points: Data is retrieved from the person-search and property-search endpoints of stableenrich.dev and presented to the agent.
  • Boundary markers: There are no delimiters or explicit instructions to prevent the agent from interpreting API data as commands.
  • Capability inventory: The skill is capable of executing shell commands and performing network requests.
  • Sanitization: The skill does not describe or implement validation or sanitization for the data received from the external service.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 02:55 AM
Security Audit — agent-trust-hub — people-property