docs-seeker
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to perform a global installation of the 'repomix' package (
npm install -g repomix) if it is not found on the system. Installing software at runtime from unverified sources introduces significant supply chain risks. - [EXTERNAL_DOWNLOADS]: The skill heavily prioritizes 'context7.com' as the primary source for all documentation lookups. This is a third-party, non-trusted documentation aggregator, which presents privacy risks regarding user research topics and potential for content poisoning.
- [COMMAND_EXECUTION]: The skill uses multiple shell commands, including
git cloneto download repositories to/tmpandrepomixto process them. Additionally, the error handling documentation suggests usingpkill -9to manage hung processes anddf/freeto monitor system resources. - [PRIVILEGE_ESCALATION]: The instruction to install npm packages globally and the suggestion to use
pkillfor process management involve operations that typically require elevated system privileges. - [INDIRECT_PROMPT_INJECTION]: The skill has a large attack surface for indirect prompt injection as it retrieves and processes documentation from third-party aggregators and arbitrary GitHub repositories.
- Ingestion points: The skill performs
WebFetchonllms.txtfiles from various sources and readsrepomix-output.xmlgenerated from cloned GitHub repositories (SKILL.md, references/tool-selection.md). - Boundary markers: No specific delimiters or "ignore instructions" warnings are provided to the sub-agents (Explorer/Researcher) when they process this potentially untrusted external content (SKILL.md).
- Capability inventory: The skill possesses the capability to execute shell commands (
git,npm,repomix) and perform network operations (WebFetch) (SKILL.md, references/tool-selection.md). - Sanitization: Content retrieved from external sources is not sanitized or validated before being analyzed by the agents (references/best-practices.md).
Audit Metadata