ctx-insight
Warn
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
ctx_insighttool performs an automated installation of dependencies upon its first execution. The skill does not specify the origin or the list of packages being retrieved, which represents an unverifiable external download risk.- [COMMAND_EXECUTION]: The skill triggers thectx_insighttool which executes several system-level operations including copying source files to a cache, compiling a dashboard interface, and launching a local web server on port 4747.- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection.- Ingestion points: The dashboard aggregates and processes session activity, tool usage, and project focus metrics (SKILL.md).- Boundary markers: No delimiters or warnings are provided to the agent regarding potential instructions embedded in the processed metrics.- Capability inventory: The associated tool has the capacity to install external packages and run a network server.- Sanitization: The instructions do not define any sanitization or validation steps for the ingested data.
Audit Metadata