people-property
Warn
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install and run the
agentcashnpm package, which is not from a recognized trusted organization or explicitly linked to the author's vendor patterns. This includes both global installation and the use ofnpxfor runtime execution. - [COMMAND_EXECUTION]: The skill uses
npxandnpmshell commands to perform core tasks, including fetching data and managing account settings. This execution path could be targeted if inputs are not properly sanitized. - [DATA_EXFILTRATION]: Search queries containing sensitive personal information (names, addresses) are sent to
stableenrich.dev, an external domain not associated with the vendor or the approved whitelist. - [INDIRECT_PROMPT_INJECTION]: The skill processes structured responses from an external API, creating a surface for potential injection attacks if the API returns malicious content.
- Ingestion points: Data is retrieved from the
person-searchandproperty-searchendpoints ofstableenrich.devand presented to the agent. - Boundary markers: There are no delimiters or explicit instructions to prevent the agent from interpreting API data as commands.
- Capability inventory: The skill is capable of executing shell commands and performing network requests.
- Sanitization: The skill does not describe or implement validation or sanitization for the data received from the external service.
Audit Metadata