ctx-insight

Warn

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The ctx_insight tool performs an automated installation of dependencies upon its first execution. The skill does not specify the origin or the list of packages being retrieved, which represents an unverifiable external download risk.- [COMMAND_EXECUTION]: The skill triggers the ctx_insight tool which executes several system-level operations including copying source files to a cache, compiling a dashboard interface, and launching a local web server on port 4747.- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection.- Ingestion points: The dashboard aggregates and processes session activity, tool usage, and project focus metrics (SKILL.md).- Boundary markers: No delimiters or warnings are provided to the agent regarding potential instructions embedded in the processed metrics.- Capability inventory: The associated tool has the capacity to install external packages and run a network server.- Sanitization: The instructions do not define any sanitization or validation steps for the ingested data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 5, 2026, 03:46 AM